Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-17532
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting

The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up to, and including, 2.29.15. This is due to the CacheExtractPreparePageParams() function using PHP's loose inequality operator (!=) to compare the expected HMAC string against the JSON-decoded 'nonce' value — supplying the JSON boolean true causes any non-empty HMAC string to compare as loosely equal, bypassing the signature check — combined with insufficient output escaping in the _CbContentFinishSkip() function, which concatenates the attacker-controlled 'selfTest' field directly into the HTML response body. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.

Affected products

Seraphinite Accelerator
  • =<2.29.18
Dismissed
(no matching packages found)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
None

None

Affected products

Dismissed
(no matching packages found)
Permalink CVE-2026-20313
7.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco Catalyst SD-WAN Security Hardening Release - Memory Corruption Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20313 are related to Improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-1284.

Affected products

Cisco Catalyst SD-WAN Manager
  • ==20.15.4.4_LI_Images
  • ==20.4.2.0.4
  • ==18.3.0
  • ==20.6.3.0.14
  • ==20.12.4
  • ==20.6.2.1
  • ==20.4.2.2.2
  • ==20.6.5.1.3
  • ==20.9.9_LI_Images
  • ==18.4.3
  • ==20.6.3
  • ==20.15.5_LI_Images
  • ==20.18.2_LI_Images
  • ==20.3.3.0.8
  • ==20.5.1.1
  • ==20.6.3.0.23
  • ==20.12.5.3_LI_Images
  • ==20.6.3.0.40
  • ==18.4.0
  • ==20.9.8.2_LI_Images
  • ==20.4.2.1.1
  • ==20.10.1_LI_Images
  • ==20.9.5.1_LI_Images
  • ==20.9.3
  • ==20.9.5.2.13
  • ==18.4.6
  • ==20.18.3
  • ==20.6.3.0.18
  • ==20.9.4.1.1
  • ==20.6.3.1.1
  • ==20.18.1
  • ==20.9.9.1_LI_Images
  • ==20.3.4.2.2
  • ==20.6.3.0.46
  • ==20.6.5.1.4
  • ==18.4.1
  • ==20.12.4_LI_Images
  • ==20.3.2_928
  • ==19.2.1
  • ==20.6.3.0.19
  • ==20.4.1
  • ==20.12.7_LI_Images
  • ==20.3.4.0.9
  • ==20.6.3.0.11
  • ==20.4.1.0.01
  • ==20.12.4.0.4
  • ==20.18.2.1_LI_Images
  • ==20.8.1
  • ==20.13.1_LI_Images
  • ==20.3.8
  • ==20.3.3.1.2
  • ==26.1.1.2_LI_Images
  • ==20.3.4.0.19
  • ==20.3.1
  • ==20.9.6_LI_Images
  • ==20.6.1.1
  • ==20.3.4.1.2
  • ==20.6.5.2
  • ==20.15.4.3_LI_Images
  • ==20.12.5
  • ==20.15.4.5_LI_Images
  • ==20.6.5.2.8
  • ==20.1.1.1
  • ==20.12.5.2_LI_Images
  • ==20.4.2
  • ==20.12.4_Monthly_ES5
  • ==17.2.5
  • ==20.3.814
  • ==20.3.2_937
  • ==20.9.5.1.4
  • ==17.2.7
  • ==20.6.5.1.11
  • ==20.3.3.1.5
  • ==26.1.1.1_LI_Images
  • ==20.15.2
  • ==20.6.3.0.5
  • ==20.15.5.2
  • ==20.6.3.0.41
  • ==20.6.3.3
  • ==20.12.6_LI_Images
  • ==20.6.8
  • ==20.9.4.1.6
  • ==20.9.7.1_LI _Images
  • ==20.9.4.0.4
  • ==20.6.5.1.5
  • ==20.12.501
  • ==20.4.2.0.1
  • ==20.6.3.0.38
  • ==20.15.4.1_LI_Images
  • ==19.1.0
  • ==20.12.6.1
  • ==20.6.6.0.1
  • ==20.12.5_LI_Images
  • ==18.4.302
  • ==20.3.3.0.4
  • ==20.6.5.1.6
  • ==20.12.5.2
  • ==19.2.4.0.1
  • ==20.18.2.2
  • ==20.9.4.1
  • ==20.15.3.1
  • ==19.3.0
  • ==20.3.4.2
  • ==20.12.6.2_LI_Images
  • ==20.9.1EFT2
  • ==20.9.9
  • ==20.9.8
  • ==20.15.4_LI_Images
  • ==20.4.2.2.8
  • ==20.3.7.2
  • ==20.6.5.5
  • ==20.7.1EFT2
  • ==18.4.0.1
  • ==20.6.2.2
  • ==20.6.5.1.9
  • ==20.9.3.0.16
  • ==20.9.9.2
  • ==20.16.1_LI_Images
  • ==20.12.5.3
  • ==20.9.3.2
  • ==20.15.1
  • ==20.9.3.0.12
  • ==20.6.4.1
  • ==20.15.5.2_LI_Images
  • ==20.3.5
  • ==26.1.1.2
  • ==19.2.4.0.8
  • ==20.9.3_LI_ Images
  • ==20.9.3.0.23
  • ==20.3.3.1.7
  • ==20.6.3.0.29
  • ==20.6.5.4
  • ==20.3.2.1_927
  • ==20.9.7.1
  • ==18.3.4
  • ==19.2.099
  • ==20.1.2_937
  • ==19.2.4
  • ==20.3.4.1.1
  • ==20.6.2.2.2
  • ==20.6.5.1.10
  • ==20.6.5.1.7
  • ==20.6.3.0.45
  • ==20.6.3.0.25
  • ==18.3.3.1
  • ==20.4.1.1
  • ==20.18.3_LI_Images
  • ==20.18.3.1
  • ==20.6.2.2.7
  • ==20.3.4.0.24
  • ==20.6.1.2
  • ==20.3.2_925
  • ==20.7.1.0.2
  • ==20.9.2.1
  • ==20.12.2_LI_Images
  • ==18.3.5
  • ==20.6.2
  • ==20.18.2.2_LI_Images
  • ==20.12.7
  • ==20.6.3.0.32
  • ==17.2.6
  • ==20.3.4.0.20
  • ==20.9.3.0.20
  • ==20.9.4.1.3
  • ==20.15.3
  • ==17.2.4
  • ==20.4.2.2
  • ==20.3.7
  • ==20.6.5.2.3
  • ==20.12.5.1
  • ==20.12.7.2_LI_Images
  • ==20.4.2.2.1
  • ==20.9.3.0.4
  • ==20.6.5.3
  • ==20.9.5.1
  • ==20.10.1.1
  • ==20.6.4.2
  • ==20.6.5.1
  • ==20.12.6.2
  • ==20.3.3.0.2
  • ==20.6.3.0.27
  • ==20.4.1.0.1
  • ==20.12.1
  • ==20.9.5.2
  • ==20.9.3.0.5
  • ==20.3.4.0.6
  • ==19.0.1a
  • ==20.9.5_LI_Images
  • ==20.15.2_LI_Images
  • ==20.6.3.2
  • ==20.9.2.3
  • ==20.9.7_LI _Images
  • ==19.2.097
  • ==18.3.3
  • ==20.6.4.0.4
  • ==20.12.5.1.01
  • ==20.18.2
  • ==17.2.10
  • ==20.1.12
  • ==20.15.4.1
  • ==20.9.5.2.16
  • ==20.9.3.1
  • ==20.9.3.0.18
  • ==20.9.5.2.14
  • ==20.6.4.0.21
  • ==26.1.1_LI_Images
  • ==20.15.1_LI_Images
  • ==20.6.5.1.13
  • ==20.3.3
  • ==20.9.5
  • ==20.6.3.0.2
  • ==20.4.2.3
  • ==20.4.1.1.5
  • ==20.6.0.18.4
  • ==20.15.4
  • ==20.12.5.4
  • ==19.2.098
  • ==20.10.1
  • ==20.5.1.0.1
  • ==20.12.4.1
  • ==20.9.5.3
  • ==20.15.5.1_LI_Images
  • ==20.12.4.0.03
  • ==20.9.5.2.21
  • ==20.1.2
  • ==20.6.3.1
  • ==20.6.2.0.4
  • ==20.3.6
  • ==20.3.3.1.1
  • ==20.5.1.2
  • ==20.3.2.1_930
  • ==20.9.1
  • ==20.12.401
  • ==17.2.9
  • ==19.2.2
  • ==20.6.5.1.14
  • ==20.9.8.2
  • ==20.9.9.1
  • ==20.12.6.1_LI_Images
  • ==26.0.1
  • ==20.5.1.0.2
  • ==20.3.4.2.1
  • ==20.9.1.1
  • ==20.3.4.1
  • ==20.9.9.2_LI_Images
  • ==20.15.4.2
  • ==20.7.1
  • ==20.3.3.0.14
  • ==20.9.3.0.29
  • ==20.6.3.0.10
  • ==18.4.4
  • ==19.2.31
  • ==20.1.1
  • ==18.4.5
  • ==20.12.5.1_LI_Images
  • ==20.3.4
  • ==20.12.3_LI_Images
  • ==20.15.3_ LI _Images
  • ==20.4.1.0.02
  • ==19.2.929
  • ==20.4.2.2.3
  • ==20.9.5.2_LI_Images
  • ==20.9.1_LI_Images
  • ==18.3.6
  • ==20.9.6.0.3
  • ==20.3.4.0.1
  • ==18.4.501_ES
  • ==20.9.5.2.1
  • ==19.2.32
  • ==20.12.5.4_LI_ Images
  • ==20.1.3.1
  • ==20.9.2.0.01
  • ==20.12.7.1_LI_Images
  • ==20.6.2.2.4
  • ==20.3.5.0.7
  • ==20.3.5.1
  • ==20.3.3.1
  • ==26.1.1.1
  • ==19.0.0
  • ==20.9.3.0.7
  • ==20.3.4.0.11
  • ==20.6.3.0.47
  • ==20.11.1.2
  • ==20.5.1
  • ==20.3.4.0.25
  • ==20.9.3.2_LI_Images
  • ==20.11.1.1
  • ==20.12.7.2
  • ==20.6.1.0.1
  • ==20.9.5.2.7
  • ==20.3.3.2
  • ==20.3.3.0.17
  • ==20.9.4_LI_Images
  • ==20.6.5.2.4
  • ==20.12.2
  • ==20.3.813
  • ==18.2.0
  • ==20.12.6
  • ==20.6.5
  • ==20.3.2.0.5
  • ==20.13.1
  • ==20.9.3.0.3
  • ==18.3.1.1
  • ==20.9.3.0.2
  • ==20.3.2
  • ==20.16.1
  • ==20.12.3
  • ==20.6.2.2.3
  • ==19.2.0
  • ==19.2.3
  • ==20.4.2.2.4
  • ==18.3.7
  • ==20.1.3
  • ==20.18.2.1
  • ==20.9.7
  • ==20.7.2
  • ==20.9.3.0.24
  • ==20.4.2.1
  • ==20.15.4.2_LI_Images
  • ==20.15.5.3
  • ==18.3.6.1
  • ==20.6.5.1.2
  • ==20.12.4.0.6
  • ==20.10.1.2
  • ==20.9.4.1_LI_Images
  • ==20.15.5.3_LI_Images
  • ==20.9.6
  • ==20.15.4.3
  • ==20.11.1_LI_Images
  • ==20.3.7.1
  • ==20.6.3.0.31
  • ==20.7.1.1
  • ==20.6.4.0.19
  • ==20.6.3.0.33
  • ==20.9.3.0.8
  • ==20.6.5.2.1
  • ==20.3.3.0.16
  • ==20.14.1
  • ==18.3.1
  • ==20.5.0.1.1
  • ==20.3.4.0.5
  • ==20.15.5.1
  • ==20.4.2.0.2
  • ==20.14.1_LI_Images
  • ==19.2.4.0.9
  • ==20.15.5
  • ==18.3.8
  • ==20.18.3.1_LI_Images
  • ==20.18.1_LI_Images
  • ==20.9.2_LI_Images
  • ==20.12.1_LI_Images
  • ==20.3.5.0.9
  • ==20.9.3.0.21
  • ==20.9.3.0.17
  • ==20.11.1
  • ==20.3.2.1
  • ==20.3.4.3
  • ==20.6.6
  • ==20.6.3.0.51
  • ==20.3.5.0.8
  • ==20.3.2.0.6
  • ==20.12.3.1
  • ==20.6.7
  • ==20.3.3.0.18
  • ==20.9.2.2
  • ==20.9.8_LI_Images
  • ==20.15.4.5
  • ==20.9.3.0.25
  • ==20.9.3.0.26
  • ==20.9.4
  • ==20.3.4.0.26
  • ==20.3.2_929
  • ==20.15.4.4
  • ==20.6.3.0.7
  • ==17.2.8
  • ==20.12.4.1_LI_Images
  • ==20.3.3.1.10
  • ==20.6.3.4
  • ==20.12.7.1
  • ==20.6.3.0.39
  • ==20.6.1
  • ==20.9.2
  • ==20.6.4
  • ==20.9.5.3_LI_Images
  • ==26.1.1
  • ==20.6.0.18.3
  • ==18.4.303
  • ==20.4.1.2
Cisco Catalyst SD-WAN Controller
  • ==20.12.2
  • ==20.9.9
  • ==18.2.0
  • ==20.9.8
  • ==20.12.6
  • ==20.6.5
  • ==20.1.12
  • ==20.15.4.1
  • ==18.3.0
  • ==20.9.3.1
  • ==20.12.4
  • ==20.3.7.2
  • ==20.13.1
  • ==20.3.3
  • ==20.3.2
  • ==20.6.3
  • ==18.4.3
  • ==20.16.1
  • ==20.12.3
  • ==20.9.5
  • ==20.9.9.2
  • ==20.12.5.3
  • ==19.2.0
  • ==20.15.1
  • ==20.4.2.3
  • ==19.2.3
  • ==18.3.7
  • ==18.4.0
  • ==20.15.4
  • ==20.12.5.4
  • ==19.2.098
  • ==20.10.1
  • ==20.1.3
  • ==20.6.4.1
  • ==20.18.2.1
  • ==20.9.7
  • ==20.3.5
  • ==20.7.2
  • ==20.9.3
  • ==20.12.4.1
  • ==20.9.5.3
  • ==26.1.1.2
  • ==18.4.6
  • ==20.18.3
  • ==20.18.1
  • ==20.15.5.3
  • ==20.3.6
  • ==20.1.2
  • ==18.4.1
  • ==20.6.5.4
  • ==20.9.7.1
  • ==18.3.4
  • ==19.2.099
  • ==19.2.4
  • ==19.2.1
  • ==20.9.1
  • ==20.4.1
  • ==20.9.6
  • ==20.4.1.1
  • ==20.15.4.3
  • ==17.2.9
  • ==20.18.3.1
  • ==19.2.2
  • ==20.8.1
  • ==20.3.7.1
  • ==20.3.8
  • ==20.6.1.2
  • ==20.9.8.2
  • ==20.9.9.1
  • ==18.3.5
  • ==20.6.2
  • ==20.12.7
  • ==20.3.1
  • ==20.15.4.2
  • ==20.14.1
  • ==20.7.1
  • ==18.3.1
  • ==20.6.5.2
  • ==17.2.6
  • ==20.15.5.1
  • ==20.12.5
  • ==20.15.5
  • ==18.3.8
  • ==20.15.3
  • ==17.2.4
  • ==18.4.4
  • ==20.1.1
  • ==19.2.31
  • ==18.4.5
  • ==20.3.7
  • ==20.12.5.1
  • ==20.4.2
  • ==20.3.4
  • ==17.2.5
  • ==20.6.5.3
  • ==20.9.5.1
  • ==19.2.929
  • ==20.10.1.1
  • ==17.2.7
  • ==20.11.1
  • ==18.3.6
  • ==20.3.4.3
  • ==20.12.6.2
  • ==19.2.32
  • ==20.6.6
  • ==20.15.2
  • ==20.15.5.2
  • ==20.1.3.1
  • ==20.12.3.1
  • ==20.6.3.3
  • ==20.6.7
  • ==20.6.8
  • ==20.9.2.2
  • ==20.15.4.5
  • ==20.12.1
  • ==20.3.5.1
  • ==26.1.1.1
  • ==20.9.4
  • ==19.0.0
  • ==20.15.4.4
  • ==17.2.8
  • ==19.1.0
  • ==20.12.6.1
  • ==19.0.1a
  • ==20.5.1
  • ==20.11.1.1
  • ==20.12.7.1
  • ==20.12.7.2
  • ==20.6.3.2
  • ==20.9.2.3
  • ==20.12.5.2
  • ==20.6.1
  • ==20.9.2
  • ==20.18.2.2
  • ==20.6.4
  • ==19.2.097
  • ==20.3.3.2
  • ==18.3.3
  • ==26.1.1
  • ==20.18.2
  • ==18.4.303
  • ==19.3.0
  • ==20.4.1.2
  • ==17.2.10
Dismissed
(no matching packages found)
Permalink CVE-2026-71251
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Akaunting: Cross-Company Media IDOR in Customer Portal Download Endpoint

Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download(), reachable at uploads/{id}/download behind only generic auth middleware) fetched the requested Media record by ID with no verification that it belonged to the requesting portal customer's own company, allowing any authenticated portal customer to download any other company's uploaded files by guessing or enumerating media IDs. Fixed in commit 80ef6d3 (2026-07-12), which added an explicit ownership check comparing the media's parent record contact_id against the requesting user's own contact.

Affected products

akaunting
  • ==0
Dismissed
(no matching packages found)
Permalink CVE-2026-71235
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Magistrala IoT Platform: Unrestricted Go/Lua Script Execution in Rules Engine

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Go script engine (re/golang.go) runs scripts through the Yaegi interpreter with stdlib.Symbols, exposing the full Go standard library (including os and net/http) with validation limited to a regex blocking goroutines and panic() calls; dangerous functions such as os.ReadFile, os.WriteFile, os.Remove, and os.Environ remain fully accessible. The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal). An authenticated low-privileged user can achieve arbitrary file read/write, environment variable leakage, database access, and SSRF against internal microservices.

Affected products

magistrala
  • ==0
Dismissed
(no matching packages found)
Permalink CVE-2026-20272
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cisco IOS XE Software Security Hardening Release

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.

Affected products

Cisco IOS XE Software
  • ==17.15.1y
  • ==17.3.1x
  • ==16.12.1z1
  • ==16.6.5b
  • ==16.12.9
  • ==16.9.2s
  • ==16.12.1s
  • ==17.18.1
  • ==17.15.4
  • ==16.6.5
  • ==17.12.1z2
  • ==17.12.1x
  • ==16.9.3h
  • ==16.9.7
  • ==17.1.2
  • ==16.8.1a
  • ==17.12.5
  • ==17.12.4b
  • ==17.7.1a
  • ==17.2.1
  • ==16.7.1
  • ==16.10.1a
  • ==16.12.4
  • ==17.3.1w
  • ==17.3.3
  • ==17.6.8
  • ==16.12.13
  • ==16.8.2
  • ==16.6.6
  • ==16.9.1b
  • ==17.10.1b
  • ==16.9.8
  • ==17.9.6a
  • ==17.11.1a
  • ==17.9.1
  • ==17.12.1z5
  • ==16.12.7
  • ==17.9.4a
  • ==16.12.5
  • ==17.6.1x
  • ==17.15.4a
  • ==16.10.3
  • ==17.12.7
  • ==16.10.1s
  • ==16.12.4a
  • ==17.2.1r
  • ==17.7.1b
  • ==17.12.3a
  • ==16.12.2a
  • ==17.3.6
  • ==16.12.2
  • ==17.4.2
  • ==17.9.5b
  • ==16.9.1d
  • ==17.9.1y1
  • ==17.1.1a
  • ==17.1.3
  • ==17.15.4b
  • ==16.11.1s
  • ==17.3.5a
  • ==16.12.1c
  • ==16.9.5
  • ==16.6.5a
  • ==17.18.3a
  • ==17.15.1b
  • ==17.12.4a
  • ==17.3.5
  • ==16.12.1t
  • ==16.6.4a
  • ==17.6.4
  • ==17.9.5d
  • ==17.12.1y
  • ==16.7.4
  • ==17.11.1
  • ==17.17.1
  • ==16.12.8
  • ==17.18.1y
  • ==16.9.8b
  • ==16.9.1a
  • ==17.9.5c
  • ==16.6.3
  • ==17.9.1w
  • ==17.9.7b
  • ==17.12.1
  • ==17.7.1
  • ==17.13.1a
  • ==17.9.2a
  • ==17.6.7
  • ==17.15.5
  • ==17.15.3a
  • ==17.3.8
  • ==17.4.1
  • ==17.4.1c
  • ==17.5.1a
  • ==17.9.3a
  • ==17.9.5a
  • ==17.3.2
  • ==17.15.2c
  • ==17.12.1z4
  • ==16.10.1c
  • ==17.14.1a
  • ==16.12.10a
  • ==16.9.3
  • ==17.1.1s
  • ==17.6.6a
  • ==17.3.4c
  • ==17.8.1
  • ==16.12.1z2
  • ==17.6.2
  • ==16.12.15
  • ==17.9.4
  • ==17.12.6a
  • ==17.3.1
  • ==17.4.1b
  • ==17.4.1a
  • ==17.18.3
  • ==17.12.3
  • ==17.15.4c
  • ==16.12.1w
  • ==16.12.1
  • ==16.12.6a
  • ==17.6.1z
  • ==17.12.1z
  • ==17.15.3b
  • ==16.9.6
  • ==16.12.1x
  • ==17.14.1
  • ==17.18.1a
  • ==16.6.8
  • ==17.15.1
  • ==17.6.3
  • ==17.12.5d
  • ==16.12.11
  • ==17.15.1x
  • ==17.3.1z
  • ==16.10.1
  • ==17.10.1a
  • ==16.6.4s
  • ==17.3.8a
  • ==17.9.7
  • ==17.9.5e
  • ==16.9.8a
  • ==16.8.1c
  • ==16.6.7a
  • ==16.9.3a
  • ==16.8.1e
  • ==16.10.2
  • ==16.6.9
  • ==17.2.1a
  • ==17.18.2
  • ==16.9.5f
  • ==17.1.1t
  • ==17.15.2b
  • ==17.18.1w
  • ==16.9.2
  • ==17.2.2
  • ==17.9.2
  • ==16.9.1
  • ==17.3.5b
  • ==16.9.4
  • ==17.12.6b
  • ==16.6.7
  • ==16.10.1e
  • ==17.6.1a
  • ==17.12.1z1
  • ==17.6.6
  • ==16.11.1b
  • ==16.8.1
  • ==16.11.2
  • ==17.15.2
  • ==17.18.1z
  • ==17.9.3
  • ==16.9.2a
  • ==17.6.1
  • ==17.12.1a
  • ==16.7.3
  • ==17.12.1z6
  • ==17.10.1
  • ==17.15.7
  • ==16.7.2
  • ==16.8.1b
  • ==16.10.1f
  • ==16.12.1z
  • ==17.15.4s1
  • ==17.3.2a
  • ==16.12.6
  • ==16.12.2t
  • ==17.7.2
  • ==16.12.2s
  • ==17.3.7
  • ==17.9.1x1
  • ==16.12.3
  • ==16.12.16
  • ==17.3.4b
  • ==16.6.2
  • ==17.15.5a
  • ==17.12.2
  • ==17.6.8a
  • ==17.9.7a
  • ==16.8.1d
  • ==16.12.1y
  • ==17.1.1
  • ==17.3.4
  • ==17.6.5a
  • ==17.12.5a
  • ==17.12.2a
  • ==16.11.1
  • ==17.6.5
  • ==17.15.3
  • ==17.15.1a
  • ==16.12.12
  • ==17.15.4d
  • ==17.12.7b
  • ==17.3.4a
  • ==16.9.3s
  • ==16.7.1a
  • ==16.12.3a
  • ==16.11.1c
  • ==17.3.3a
  • ==16.12.1a
  • ==17.9.1x
  • ==17.9.1a
  • ==17.8.1a
  • ==16.10.1b
  • ==16.9.1c
  • ==17.9.5f
  • ==17.6.1z1
  • ==16.12.14
  • ==16.11.1a
  • ==16.8.1s
  • ==17.12.1w
  • ==16.12.10
  • ==17.2.1v
  • ==16.6.10
  • ==17.12.6
  • ==17.9.8
  • ==17.4.2a
  • ==17.15.1w
  • ==17.15.2a
  • ==17.9.1y
  • ==16.12.5a
  • ==17.12.1z3
  • ==16.10.1g
  • ==17.2.3
  • ==16.8.3
  • ==17.16.1a
  • ==16.9.1s
  • ==16.12.5b
  • ==16.9.4c
  • ==16.6.4
  • ==17.12.5b
  • ==17.5.1
  • ==16.12.3s
  • ==17.12.5c
  • ==17.9.9
  • ==17.6.3a
  • ==17.12.7a
  • ==26.1.1a
  • ==17.12.4
  • ==26.1.1
  • ==17.9.5
  • ==17.3.1a
  • ==17.18.1x
  • ==17.16.1
  • ==17.9.6
  • ==17.13.1
  • ==16.10.1d
  • ==16.7.1b
Dismissed
(no matching packages found)
Permalink CVE-2026-71204
6.2 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
changedetection.io: Omitted Checkbox in /settings Save Silently Disables API Key Enforcement

changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update(). Because WTForms represents an unchecked checkbox as False rather than 'unchanged', and only the 'password' field is special-cased against this problem, a POST to /settings that omits the api_access_token_enabled field (e.g. a minimal scripted request) silently disables API key enforcement for the entire REST API, exposing the full watch list, history, and configuration to unauthenticated requests.

Affected products

changedetection.io
  • ==0.55.7
Dismissed
(no matching packages found)
Permalink CVE-2026-16442
7.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.

References

Affected products

keycloak-services
rhbk/keycloak-rhel9
  • *
rhbk/keycloak-rhel9-operator
  • *
rhbk/keycloak-operator-bundle
  • *
rhbk-keycloak-rhel9/rhbk-keycloak-rhel9
rhbk-openshift-rhel9/rhbk-openshift-rhel9
Dismissed
(no matching packages found)
Permalink CVE-2026-10059
9.1 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via clustercurator serviceaccount token

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.

References

Affected products

multicluster-engine/cluster-curator-controller-rhel9
Dismissed
(no matching packages found)
Permalink CVE-2026-16102
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.

References

Affected products

keycloak-services
rhbk/keycloak-rhel9
  • *
rhbk/keycloak-rhel9-operator
  • *
rhbk/keycloak-operator-bundle
  • *
rhbk-keycloak-rhel9/rhbk-keycloak-rhel9
rhbk-openshift-rhel9/rhbk-openshift-rhel9