UPDATED 2026-07-25

Live Threat Feed

A continuously updated record of high severity software supply chain attacks and actively exploited vulnerabilities that 0Day surfaces automatically. Each entry climbs a three stage confidence pipeline: Candidate → Early WarningConfirmed, and pages update automatically as new sources corroborate a threat.

EARLY WARNINGMAVENJULY 2026
Fastjson 1.x RCE Vulnerability Targeted in Attacks: Early WarningEarly warning: Fastjson 1.x RCE vulnerability targeted in attacks. Assess your Spring Boot application exposure.
EARLY WARNINGNPMJULY 2026
SiYuan Missing Authorization Vulnerability Under InvestigationSiYuan before v3.7.2 reportedly contains a critical missing authorization vulnerability allowing remote unauthenticated access.
EARLY WARNINGCARGOJULY 2026
aws-smithy-http-server <= 0.66.4 Vulnerable to Slowloris DoSaws-smithy-http-server <= 0.66.4 reportedly allows unauthenticated Slowloris denial of service due to missing timeouts and connection limits.
EARLY WARNINGNPMJULY 2026
Quasar npm Package <=2.20.1: Prototype Pollution VulnerabilityEarly warning: Quasar npm package <=2.20.1 may be vulnerable to prototype pollution through its extend() utility.
EARLY WARNINGNPMJULY 2026
shescape npm Package Vulnerability: Shell Injection Risk on WindowsEarly warning: shescape npm package is under investigation for a shell injection vulnerability on Windows with CMD.
EARLY WARNINGPYPIJULY 2026
AWS API MCP Server Security Policy Bypass Under InvestigationEarly warning: AWS API MCP Server may silently bypass security policies due to initialization failure.
EARLY WARNINGNPMJULY 2026
blaze-server HTTP/1.1 Trailer Field Vulnerability: Early WarningEarly warning: blaze-server may merge HTTP/1.1 chunked-body trailer fields into Request.headers, allowing header injection.
EARLY WARNINGNPMJULY 2026
sm-crypto npm Package: Predictable SM2 Key Generation VulnerabilityEarly warning: sm-crypto npm package reportedly uses predictable RNG for SM2 key generation.
EARLY WARNINGCARGOJULY 2026
Hubuum Client Library Vulnerability: Authenticated Requests May Escape Base PathEarly warning: Hubuum client library for Rust may expose sensitive data through redirects.
EARLY WARNINGGOJULY 2026
Integer Overflow Vulnerability in frp SSH Tunnel GatewayAn integer-overflow vulnerability in the frp server's SSH Tunnel Gateway may allow unauthenticated remote denial of service.
EARLY WARNINGMAVENJULY 2026
OpenDJ SASL PLAIN Authentication Vulnerability: Early WarningEarly warning of a potential vulnerability in OpenDJ SASL PLAIN authentication mechanism that may allow privilege escalation.
EARLY WARNINGMAVENJULY 2026
OpenDJ DSMLv2 Gateway Vulnerability: SSRF, File Read, DoSEarly warning: OpenDJ DSMLv2 SOAP gateway may allow SSRF, local file read, and DoS. Upgrade to version 5.1.2.
EARLY WARNINGNPMJULY 2026
Budibase REST Datasource Vulnerability: Potential Credential TheftEarly warning: Budibase may expose REST datasource credentials to unauthenticated attackers.
EARLY WARNINGNPMJULY 2026
Critical SQL Injection Vulnerability Reported in Budibase MySQL IntegrationEarly warning: A critical SQL injection vulnerability has been reported in Budibase's MySQL integration.
EARLY WARNINGPYPIJULY 2026
Open WebUI Package Vulnerability: Potential File Access ElevationEarly warning of a potential vulnerability in Open WebUI allowing file access elevation.
EARLY WARNINGGOJULY 2026
Cloudreve WOPI PUT_RELATIVE Path Traversal Vulnerability AlertEarly warning: Cloudreve's WOPI PUT_RELATIVE handler may allow path traversal and arbitrary file creation.
EARLY WARNINGPYPIJULY 2026
Open WebUI Cache Misconfiguration: Potential Cross-User Model ExposureEarly warning: Open WebUI's get_all_models handlers may expose user model lists due to a cache misconfiguration.
EARLY WARNINGGOJULY 2026
getkin/kin-openapi Package Vulnerability: Authentication Bypass ReportedEarly warning: getkin/kin-openapi may allow unauthenticated requests due to a nil AuthenticationFunc issue.
EARLY WARNINGCARGOJULY 2026
Pre-auth Panic Vulnerability in russh 0.62.2 Under InvestigationEarly warning of a pre-authentication denial-of-service vulnerability in russh 0.62.2 that could allow remote panic.
EARLY WARNINGPYPIJULY 2026
GitPython Vulnerability: Section-Name Injection Risk Under InvestigationEarly warning: GitPython <= 3.1.52 may be vulnerable to section-name injection, potentially enabling remote code execution.
EARLY WARNINGNPMJULY 2026
Potential Remote Code Execution in velocityjs v2.1.6: Early WarningEarly warning of a reported Remote Code Execution vulnerability in velocityjs v2.1.6 affecting server-side template rendering.
EARLY WARNINGNUGETJULY 2026
Integer Overflow in ImageMagick JNX Decoder: Potential Security RiskEarly warning: Integer overflow in ImageMagick JNX decoder may cause heap buffer over-write on 32-bit platforms.
EARLY WARNINGNUGETJULY 2026
ImageMagick Package Vulnerability: Heap Buffer Over-Write in fx OperationEarly warning of a potential heap buffer over-write vulnerability in ImageMagick's fx operation. Monitor for updates.
EARLY WARNINGNUGETJULY 2026
Microsoft Kiota Path Traversal Vulnerability: Early WarningEarly warning: Microsoft Kiota package may be vulnerable to path traversal attacks.
EARLY WARNINGNPMJULY 2026
seroval npm Package Type Confusion Issue: Early WarningEarly warning of a type confusion issue in seroval npm package versions <1.5.3, potentially allowing attacker-controlled deserialization side effects.
EARLY WARNINGNUGETJULY 2026
Microsoft Kiota Package Compromised via Command Injection VulnerabilityEarly warning: Microsoft Kiota package may have been compromised through a command injection vulnerability.
EARLY WARNINGNUGETJULY 2026
Microsoft Kiota Path Traversal Vulnerability: Early WarningEarly warning of a potential path traversal vulnerability in Microsoft Kiota affecting Copilot plugin manifests.
EARLY WARNINGNUGETJULY 2026
Microsoft Kiota Nuget Package Path/URL Injection VulnerabilityEarly warning of a potential path/URL injection vulnerability in Microsoft Kiota nuget package versions prior to 1.32.4.
EARLY WARNINGNUGETJULY 2026
Kiota PHP Code Generator Vulnerable to Code Injection AttackEarly warning: Kiota PHP code generator may be vulnerable to code injection. Upgrade and review generated code.
EARLY WARNINGPYPIJULY 2026
Kiota Python Code Generator Vulnerable to Arbitrary Code ExecutionEarly warning: Kiota Python code generator may execute arbitrary code from malicious OpenAPI specs.
EARLY WARNINGNPMJULY 2026
@better-auth/scim npm Package: Account Takeover RiskEarly warning: @better-auth/scim npm package may have account takeover and stale access issues.
EARLY WARNINGPYPIJULY 2026
mrmustard 0.7.4 PyPI Package Compromised: Credential Stealer AlertEarly warning: mrmustard 0.7.4 on PyPI reportedly steals SSH, AWS, and Kubernetes credentials.
EARLY WARNINGNUGETJULY 2026
Use-After-Free Vulnerability in ImageMagick's FormatMagickCaptionEarly warning: A use-after-free vulnerability in ImageMagick's FormatMagickCaption method is under investigation.
EARLY WARNINGNUGETJULY 2026
ImageMagick HTML Encoder Code Injection VulnerabilityAn incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder of the ImageMagick package.
EARLY WARNINGNUGETJULY 2026
ImageMagick NuGet Package: Use-After-Free Vulnerability Under InvestigationEarly warning: ImageMagick NuGet package reportedly has a use-after-free vulnerability. Monitor for updates.
EARLY WARNINGNPMJULY 2026
9router npm Package Under Investigation for Critical Supply-Chain VulnerabilitiesEarly warning: 9router npm package reportedly contains critical vulnerabilities allowing remote code execution.
EARLY WARNINGNPMJULY 2026
Cal.com Vulnerability: Critical Remote Code Execution RiskEarly warning: Cal.com before 5.9.9 may be vulnerable to unauthenticated remote code execution.
EARLY WARNINGWORDPRESSJULY 2026
SAML SSO Login WordPress Plugin Vulnerable to Authentication BypassEarly warning: SAML SSO Login WordPress plugin <= 5.4.4 reportedly vulnerable to Authentication Bypass, allowing unauthenticated access.
EARLY WARNINGNPMJULY 2026
SoftVC VITS npm Package Path Traversal Vulnerability Under InvestigationEarly warning: SoftVC VITS npm package may contain a critical path traversal vulnerability allowing file exfiltration.
EARLY WARNINGNPMJULY 2026
h2oGPT <=0.2.1 Path Traversal Vulnerability: Early WarningEarly warning of a critical path traversal vulnerability in h2oGPT <=0.2.1, potentially leading to remote code execution.
EARLY WARNINGNPMJULY 2026
next-auth npm Package Configuration Error: Potential Authentication BypassEarly warning: next-auth npm package may allow unauthenticated access due to configuration error.
EARLY WARNINGNPMJULY 2026
Email Normalizer Vulnerability in Auth.js: Potential Account Takeover RiskEarly warning of a vulnerability in Auth.js email normalizer that may allow account takeover.
CONFIRMEDNPMJULY 2026
Bold Reports Standalone Report Designer <= 14.1.11 Vulnerability ThreatCritical vulnerability in Bold Reports Standalone Report Designer <= 14.1.11 allows unauthorized file access.
EARLY WARNINGNPMJULY 2026
Bold Reports Standalone Report Designer Path Traversal Vulnerability AlertEarly warning: Bold Reports Standalone Report Designer <14.1.12 may allow unauthenticated file read via SVG processing.
CONFIRMEDNPMJULY 2026
SiYuan < v3.7.2 Vulnerabilities: XSS and Auth BypassSiYuan before v3.7.2 has critical XSS and auth bypass vulnerabilities. Upgrade to v3.7.2 or later.
EARLY WARNINGWORDPRESSJULY 2026
MountDev AI MCP Connector for WordPress: Critical Vulnerability ReportedEarly warning: MountDev AI MCP Connector for WordPress <=1.6.1 may allow unauthenticated access to admin-level functions.
EARLY WARNINGWORDPRESSJULY 2026
Customer Support Ticket System & Helpdesk Plugin for WordPress Under InvestigationEarly warning: potential code injection vulnerability in WordPress plugin <=6.0.5
EARLY WARNINGNPMJULY 2026
n8n npm Package Vulnerability: Improper Authorization DetectedEarly warning: n8n npm package has an improper authorization vulnerability affecting versions <2.28.0.
EARLY WARNINGNPMJULY 2026
n8n npm Package Privilege Escalation Vulnerability Under InvestigationEarly warning: n8n npm package reportedly allows SSO privilege escalation to instance owner under specific conditions.
EARLY WARNINGMAVENJULY 2026
netty maven Package WebSockets Handshaker Vulnerability: Early WarningEarly warning: netty maven WebSockets V07/V08 handshaker missing validation, enabling potential HTTP request smuggling attacks.
EARLY WARNINGMAVENJULY 2026
Netty OCSP Response Validation Issue: Early WarningEarly warning of a critical vulnerability in Netty's OcspClient affecting OCSP response validation.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
GitHub Actions Abused to Exploit CVE-2026-41940 in cPanel and WHMEarly warning: GitHub Actions reportedly abused to exploit CVE-2026-41940 in cPanel and WHM, stealing server credentials.
EARLY WARNINGNPMJULY 2026
Windmill Path Traversal Vulnerability Exploited in the WildHigh-severity Windmill flaw CVE-2026-29059 allows unauthenticated file read, actively exploited.
EARLY WARNINGNPMJULY 2026
n8n SSRF Vulnerability Under Investigation: Update RecommendedEarly warning: n8n versions before 1.123.64 may have SSRF vulnerability. Update recommended.
EARLY WARNINGNPMJULY 2026
Potential Shell Sandbox Bypass in @n8n/computer-use npm PackageEarly warning: @n8n/computer-use npm package may allow unrestricted access to host filesystem and network.
EARLY WARNINGNPMJULY 2026
SharePoint Vulnerability CVE-2026-50522 Under InvestigationEarly warning: SharePoint vulnerability CVE-2026-50522 is reportedly being exploited to steal machine keys.
EARLY WARNINGNPMJULY 2026
Microsoft SharePoint Vulnerability CVE-2026-50522 Under InvestigationEarly warning: Microsoft SharePoint reportedly contains a deserialization vulnerability allowing remote code execution.
CONFIRMEDCISA_KEVJULY 2026
Check Point SmartConsole Critical Vulnerability: Authentication BypassCheck Point SmartConsole has a critical authentication bypass vulnerability allowing full admin access.
EARLY WARNINGGEMJULY 2026
Possible XSS Vulnerability in rails-html-sanitizer GemEarly warning: a potential cross-site scripting vulnerability in rails-html-sanitizer gem with certain SVG configurations.
EARLY WARNINGGEMJULY 2026
Loofah HTML Sanitizer Vulnerability: SVG href Attribute BypassEarly warning of a vulnerability in Loofah's HTML sanitizer affecting SVG href attributes.
EARLY WARNINGNPMJULY 2026
typeorm npm Package Under Investigation for Critical VulnerabilityEarly warning: typeorm npm package may allow code execution via unsanitized template literals.
EARLY WARNINGNPMJULY 2026
lmdeploy API Server Vulnerability: Potential SSRF ThreatEarly warning: lmdeploy's API server may have a critical SSRF vulnerability allowing access to internal services.
EARLY WARNINGGOJULY 2026
Gitea's restore-repo Command Vulnerable to Local File InclusionEarly warning: Gitea's restore-repo command may allow local file inclusion via file:// URI.
EARLY WARNINGGOJULY 2026
Gitea's RSS/Atom Feed Handlers May Expose Private ContentEarly warning: Gitea's RSS/Atom feed handlers may bypass API-token scope and expose private content.
EARLY WARNINGGOJULY 2026
Gitea Vulnerability: Public Tokens May Affect Private PR BranchesEarly warning on a Gitea vulnerability allowing public tokens to update private branches.
EARLY WARNINGGOJULY 2026
Gitea PAT Scope Enforcement Bypass: Private Repo Commit Data LeakEarly warning: Gitea PAT scope enforcement bypass may leak private repo commit data.
EARLY WARNINGGOJULY 2026
Gitea Docker Images: Potential User Impersonation VulnerabilityEarly warning: Gitea Docker images may allow user impersonation via X-WEBAUTH-USER header.
EARLY WARNINGGOJULY 2026
Gitea API Vulnerability: Potential Privilege Escalation via Access TokensEarly warning: Gitea API may allow privilege escalation via access token scope escalation. Upgrade to version 1.27.0.
EARLY WARNINGGOJULY 2026
Gitea Debian Package Parser Vulnerabilities: Early WarningEarly warning of high severity vulnerabilities in Gitea's Debian package parser leading to potential denial of service.
EARLY WARNINGGOJULY 2026
Gitea Remember-Me Token Vulnerability: Persistent Attacker SessionsEarly warning: Gitea's Remember-Me token validation logic may not invalidate attacker sessions.
EARLY WARNINGGOJULY 2026
Gitea Web Release Edit Form Vulnerability Under InvestigationEarly warning: Gitea web release edit form may allow forbidden extensions, tracked as CVE-2025-68939 and GHSA-25GQ-J9JX-43PG.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
Gitea Webhook Issue: Potential Ongoing Data ExfiltrationReportedly, Gitea webhooks created by collaborators may continue firing after access revocation, leading to potential data exfiltration.
EARLY WARNINGPYPIJULY 2026
GitPython Package Reportedly Vulnerable to Command InjectionEarly warning: GitPython package versions 3.1.47 through 3.1.50-42 are under investigation for a command injection vulnerability.
EARLY WARNINGNPMJULY 2026
SVGO's removeScripts Plugin Potentially Leaves Executable Scripts IntactEarly warning: SVGO's removeScripts plugin may not remove all executable scripts, posing potential XSS risks.
EARLY WARNINGNPMJULY 2026
@vitest/browser npm Package Vulnerability: Early WarningEarly warning of a vulnerability in @vitest/browser npm package allowing arbitrary file operations.
EARLY WARNINGNPMJULY 2026
@sigstore/oci npm Package Credential Exposure Issue: Early WarningEarly warning: @sigstore/oci npm package may expose registry credentials due to a substring match vulnerability.
EARLY WARNINGMAVENJULY 2026
Jackson-databind Vulnerability: @JsonIgnore Bypassed with PropertyNamingStrategyEarly warning: Jackson-databind vulnerability allows bypassing @JsonIgnore on Record properties.
EARLY WARNINGNPMJULY 2026
Potential Denial of Service in OpenTelemetry JaegerPropagatorEarly warning of a potential denial of service vulnerability in the OpenTelemetry JaegerPropagator.
EARLY WARNINGNPMJULY 2026
fast-uri npm Package Vulnerability: Host Confusion via Failed IDN CanonicalizationEarly warning: fast-uri npm package versions >=2.3.1, <=4.0.0 may lead to host-based policy desync and unintended routing.
EARLY WARNINGNUGETJULY 2026
Potential.NET SDK Container Build Tampering Vulnerability: Early WarningEarly warning of a potential tampering vulnerability in.NET SDK container image builds. Assess your exposure now.
EARLY WARNINGNUGETJULY 2026
Elevation of Privilege Vulnerability in.NET ASP.NET Core AuthenticationEarly warning: elevation of privilege vulnerability in.NET ASP.NET Core authentication handler due to improper parsing.
EARLY WARNINGWORDPRESSJULY 2026
Ninja Forms WordPress Plugin Under Investigation for Critical VulnerabilityEarly warning: Ninja Forms plugin for WordPress Multisite has a critical authorization vulnerability.
EARLY WARNINGWORDPRESSJULY 2026
Ninja Forms WordPress Plugin: Critical XSS Vulnerability ReportedEarly warning: Ninja Forms WordPress plugin versions 3.10.4 through 3.14.9 reportedly contain a critical unauthenticated stored XSS vulnerability.
EARLY WARNINGGEMJULY 2026
Loofah Gem Vulnerability: Potential XSS via Split JavaScript URIsEarly warning: Loofah gem's allowed_uri? method may not detect split javascript: URIs, leading to potential XSS.
EARLY WARNINGPACKAGISTJULY 2026
Grav 2.0.4 Remote Code Execution Vulnerability Under InvestigationEarly warning: Grav 2.0.4 reportedly contains a critical remote code execution vulnerability.
EARLY WARNINGNPMJULY 2026
Grav api Plugin Vulnerability: Potential Account Takeover RiskEarly warning of a critical vulnerability in Grav api plugin that may allow account takeover.
CONFIRMEDNPMJULY 2026
ServiceNow AI Platform Vulnerability CVE-2026-6875 Exploited in the WildServiceNow AI Platform vulnerability CVE-2026-6875 is being actively exploited for remote code execution.
CONFIRMEDNPMJULY 2026
Langflow RCE Exploited to Deploy ENCFORGE Ransomware on AI InfrastructureLangflow RCE vulnerability CVE-2026-0770 exploited in the wild to deploy ENCFORGE ransomware targeting AI model files.
EARLY WARNINGWORDPRESSJULY 2026
Easy Form Builder WordPress Plugin Vulnerable to Critical Privilege EscalationEarly warning: Easy Form Builder plugin <=4.0.11 may allow unauthenticated privilege escalation.
EARLY WARNINGCISA_KEVJULY 2026
DD-WRT Buffer Overflow Vulnerability Under InvestigationEarly warning: DD-WRT reportedly contains a buffer overflow vulnerability that could allow code execution.
EARLY WARNINGNUGETJULY 2026
Denial of Service Vulnerability in.NET XML EncryptionEarly warning of a denial of service vulnerability in.NET XML encryption affecting.NET 8, 9, and 10.
EARLY WARNINGNUGETJULY 2026
.NET Security Feature Bypass Vulnerability Under InvestigationEarly warning:.NET 8,.NET 9, and.NET 10 may have a security feature bypass vulnerability in TLS/SSL connections.
EARLY WARNINGNUGETJULY 2026
.NET Denial of Service Vulnerability: Early WarningEarly warning of a potential denial of service vulnerability in.NET 8,.NET 9, and.NET 10.
EARLY WARNINGNUGETJULY 2026
Reported .NET Security Feature Bypass Vulnerability: What We KnowEarly warning of a reported security feature bypass vulnerability in.NET 8,.NET 9, and.NET 10 XML encryption.
EARLY WARNINGNUGETJULY 2026
.NET XML Processing Denial of Service VulnerabilityAn unverified denial of service vulnerability in.NET XML processing is under investigation.
EARLY WARNINGNUGETJULY 2026
.NET Denial of Service Vulnerability: Early WarningEarly warning of a denial of service vulnerability in.NET runtime cryptography layer.
EARLY WARNINGNPMJULY 2026
AVideo < 29.0: Critical CVE Under Investigation - Command Injection RiskEarly warning: AVideo before 29.0 reportedly contains a critical vulnerability allowing command injection.
EARLY WARNINGNPMJULY 2026
shell-quote npm Package Vulnerability: Quadratic-complexity Denial of ServiceEarly warning: shell-quote npm package has a reported quadratic-complexity denial of service vulnerability.
EARLY WARNINGPYPIJULY 2026
Mistune Package Vulnerability: Predictable Heading IDs RiskMistune package's toc plugin may allow attackers to inject HTML with predictable IDs, affecting multiple versions.
EARLY WARNINGPYPIJULY 2026
Pillow Package OS Command Injection Vulnerability on WindowsEarly warning of a potential OS command injection vulnerability in the Pillow package on Windows.
EARLY WARNINGNPMJULY 2026
Astro Reflected XSS Vulnerability: Early WarningEarly warning of a high severity reflected XSS vulnerability in Astro's View Transition CSS generator.
EARLY WARNINGNPMJULY 2026
brace-expansion npm Package: Potential DoS via Exponential-Time Expansionbrace-expansion npm package exhibits exponential-time behavior, leading to potential DoS attacks. Monitor and consider input validation.
EARLY WARNINGNPMJULY 2026
ktransformers npm Package Vulnerability: Early Warning IssuedEarly warning: ktransformers npm package <=0.6.3 reportedly contains a critical unauthenticated pickle deserialization vulnerability.
EARLY WARNINGNPMJULY 2026
GPT-SoVITS npm Package OS Command Injection Vulnerability Under InvestigationEarly warning: GPT-SoVITS npm package reportedly contains critical OS command injection vulnerability.
EARLY WARNINGPYPIJULY 2026
vLLM Package Vulnerability: Denial of Service RiskEarly warning of a potential denial of service vulnerability in the vLLM package.
EARLY WARNINGNPMJULY 2026
Axios formDataToJSON Vulnerability: Potential Denial of Service RiskEarly warning: Axios versions 0.28.0 and later may have uncontrolled recursion in formDataToJSON.
EARLY WARNINGPYPIJULY 2026
Pulpcore Path Traversal Vulnerability: Critical CVE-2026-12701 AlertEarly warning: Critical path traversal vulnerability found in pulpcore, affecting multiple versions.
EARLY WARNINGCJULY 2026
FreeRDP <=3.27.1 Buffer Overflow Vulnerability Under InvestigationFreeRDP <=3.27.1 reportedly contains a critical heap-based buffer overflow vulnerability.
EARLY WARNINGGEMJULY 2026
Malicious RubyGems Targeting Developer MachinesReportedly malicious versions of git_credential_manager, Dendreo, and fastlane RubyGems may compromise developer machines.
EARLY WARNINGGOJULY 2026
routesrv Component Exposes Sensitive Cluster Data: Early WarningEarly warning: routesrv component may expose sensitive cluster data due to lack of authentication.
CONFIRMEDWORDPRESSJULY 2026
Critical WordPress Core Flaw (CVE-2026-63030) Enables Unauthenticated RCEConfirmed: Unauthenticated attackers can execute code on vulnerable WordPress sites. Upgrade to 6.9.5 or 7.0.2.
CONFIRMEDNPMJULY 2026
Critical Vulnerability in IBM Langflow OSS: Arbitrary File WriteIBM Langflow OSS versions 1.0.0 to 1.10.0 have a critical vulnerability allowing arbitrary file writes.
CONFIRMEDNPMJULY 2026
IBM Langflow OSS Code Injection Vulnerability: Critical Threat ConfirmedCritical code injection vulnerability in IBM Langflow OSS versions up to 1.10.0 confirmed. Upgrade to 1.10.0+ to mitigate.
EARLY WARNINGPYPIJULY 2026
meta-ads-mcp Package Auth Bypass Vulnerability: Early WarningEarly warning: meta-ads-mcp package has an authentication bypass vulnerability affecting multiple versions.
EARLY WARNINGPYPIJULY 2026
plone.app.textfield Stored XSS Vulnerability: Early WarningEarly warning of a stored XSS vulnerability in plone.app.textfield affecting versions <2.0.2, <3.0.2, <4.0.1
CONFIRMEDNPMJULY 2026
Critical Vulnerability in IBM Langflow OSS: Unauthenticated User Account CreationIBM Langflow OSS versions 1.0.0 through 1.10.0 allow unauthenticated attackers to create user accounts, leading to potential RCE.
CONFIRMEDNPMJULY 2026
IBM Langflow OSS 1.0.0 to 1.10.0 Remote Code Execution VulnerabilityCritical RCE vulnerability in IBM Langflow OSS 1.0.0 to 1.10.0 allows unauthenticated attackers full remote code execution.
EARLY WARNINGMAVENJULY 2026
ArcadeDB Vulnerability Under InvestigationArcadeDB is reportedly vulnerable to privilege escalation and arbitrary file read.
EARLY WARNINGMAVENJULY 2026
ArcadeDB Privilege Escalation Vulnerability: Early WarningEarly warning of a potential privilege escalation vulnerability in ArcadeDB affecting multiple versions.
EARLY WARNINGNPMJULY 2026
Critical RCE Vulnerability in npm PackageAn unauthenticated remote attacker may be able to perform remote code execution due to incorrectly sanitized user input.
CONFIRMEDCISA_KEVJULY 2026
Fortinet FortiSandbox Vulnerabilities Exploited: CVE-2026-25089, CVE-2026-39808Fortinet FortiSandbox has confirmed OS command injection vulnerabilities. Upgrade to latest version.
EARLY WARNINGGEMJULY 2026
dd-trace-rb Gem Vulnerability: Improper W3C Baggage Header ParsingEarly warning: dd-trace-rb gem may lead to DoS via improper W3C baggage header parsing. Upgrade or set HTTP header limits.
EARLY WARNINGGEMJULY 2026
ViewComponent Gem Vulnerability: Reused Instances Retain Stale ContextEarly warning of a high severity vulnerability in ViewComponent gem affecting render context retention.
EARLY WARNINGGEMJULY 2026
ViewComponent around_render HTML-Safety Bypass: Early WarningEarly warning of a potential XSS vulnerability in ViewComponent due to HTML-unsafe strings in around_render.
EARLY WARNINGNPMJULY 2026
websocket-driver npm Package Vulnerability: Early WarningEarly warning of a high severity vulnerability in websocket-driver npm package. Upgrade to version 0.7.5.
EARLY WARNINGNPMJULY 2026
websocket-driver npm Package Under Investigation: Resource Limit Bypasswebsocket-driver npm package is under investigation for a resource limit bypass vulnerability when used with permessage-deflate.
EARLY WARNINGNPMJULY 2026
websocket-driver npm Package: Resource Limit Bypass via Message CompressionEarly warning: websocket-driver npm package may accept oversized messages due to a compression issue.
EARLY WARNINGGEMJULY 2026
websocket-driver Gem Vulnerability: Memory Exhaustion via Protocol Length HeadersEarly warning of a high severity vulnerability in websocket-driver gem affecting versions <0.8.1.
EARLY WARNINGGEMJULY 2026
websocket-driver Gem Vulnerability: Memory Exhaustion ThreatEarly warning of a high severity vulnerability in websocket-driver gem, potentially leading to memory exhaustion.
EARLY WARNINGNPMJULY 2026
AsyncAPI npm Packages Reportedly Infected with MalwareFive malicious versions of AsyncAPI packages were published to npm, delivering a remote access trojan.
EARLY WARNINGNPMJULY 2026
Grav API Plugin Vulnerability: Potential Account Takeover RiskEarly warning of a critical vulnerability in Grav API plugin that may enable account takeover.
CONFIRMEDCISA_KEVJULY 2026
Oracle E-Business Suite Vulnerability: Critical Threat to Oracle PaymentsOracle E-Business Suite contains a critical vulnerability allowing takeover of Oracle Payments.
EARLY WARNINGNPMJULY 2026
AsyncAPI npm Packages Compromised with Malicious PayloadReportedly, three AsyncAPI npm packages were compromised with an obfuscated dropper. Assess your exposure now.
CONFIRMEDCISA_KEVJULY 2026
Microsoft SharePoint Server Vulnerability CVE-2026-56164: What You Need to KnowMicrosoft SharePoint Server contains a critical vulnerability allowing unauthorized privilege elevation. Patches are available.
CONFIRMEDCISA_KEVJULY 2026
SonicWall SMA1000 Appliances Exploited: CVE-2026-15410 ConfirmedSonicWall SMA1000 Appliances face high-severity code injection vulnerability CVE-2026-15410, exploited in the wild. Patch now.
EARLY WARNINGGEMJULY 2026
Decidim Gem Vulnerability: Potential SSRF via Push Subscription EndpointEarly warning: Decidim gem's push subscription endpoint may allow SSRF attacks.
EARLY WARNINGGEMJULY 2026
Decidim HTML Content Blocks Vulnerability: Potential Script ExecutionEarly warning: Decidim gem vulnerability allows admins to store arbitrary HTML/JavaScript, potentially leading to script execution in visitor's browsers.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
Decidim Package Authorization Issue: Potential Data Corruption RiskEarly warning: Decidim package may allow unauthorized access to CSV census records, potentially corrupting verification data.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
Decidim JWT-backed Authentication Vulnerability: Early WarningEarly warning: Decidim JWT-backed authentication can reportedly be replayed across organizations.
EARLY WARNINGGEMJULY 2026
Decidim Gem Vulnerability: Verification Documents ExposedEarly warning: Decidim gem's verification admin UI exposes documents through reusable links.
EARLY WARNINGGEMJULY 2026
Decidim Gem Vulnerability: Private Exports Accessible via Reusable LinksEarly warning: Decidim gem allows unauthorized access to private exports.
EARLY WARNINGGEMJULY 2026
Decidim Gem SQL Injection Vulnerability: Early WarningEarly warning: Decidim gem's admin user search feature may allow SQL injection.
CONFIRMEDNPMJULY 2026
jscrambler 8.14.0 npm Package Compromised: Supply Chain Attack Detailsjscrambler 8.14.0 npm package compromised with malicious preinstall hook. Rotate secrets if used.
CONFIRMEDNPMJULY 2026
PraisonAI < 4.6.78 Supply-Chain Threat: Critical Vulnerabilities ConfirmedPraisonAI versions before 4.6.78 contain critical supply-chain vulnerabilities allowing arbitrary file writes and command execution.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
Windmill GitHub Action Vulnerability: Early Warning for EngineersWindmill GitHub Action <= 1.714.1 may expose script contents.
EARLY WARNINGPYPIJULY 2026
mcp-atlassian Package SSRF Vulnerability Under InvestigationReportedly, the mcp-atlassian package has an incomplete SSRF fix allowing unauthenticated SSRF. Monitor for patches.
EARLY WARNINGPYPIJULY 2026
Potential DNS-Rebinding Attack on mcp-atlassian PyPI PackageReportedly, the mcp-atlassian package on PyPI has a DNS-rebinding TOCTOU bypass of the SSRF fix. Monitor for updates.
EARLY WARNINGNPMJULY 2026
Critical Vulnerability Reported in Vikunja < 2.2.1Vikunja versions before 2.2.1 reportedly contain severe authorization flaws. Upgrade and review access controls.
EARLY WARNINGWORDPRESSJULY 2026
Instant Appointment WordPress Plugin Vulnerability (CVE-2026-15282)Potential critical vulnerability in Instant Appointment WordPress plugin <=1.2. Investigate exposure.
EARLY WARNINGWORDPRESSJULY 2026
Super Forms WordPress Plugin Vulnerable to Arbitrary File UploadSuper Forms – Drag & Drop Form Builder plugin for WordPress is reportedly vulnerable to Arbitrary File Upload, allowing remote code execution.
EARLY WARNINGCARGOJULY 2026
Rattler Package Cache Path Traversal VulnerabilityReported vulnerability in rattler_cache and py-rattler allows path traversal. Upgrade advised.
EARLY WARNINGNPMJULY 2026
Hermes WebUI Authentication Bypass Vulnerability ReportedHermes WebUI before 0.51.307 reportedly contains an authentication bypass vulnerability allowing server-side request forgery.
CONFIRMEDNPMJULY 2026
Injective npm Package Compromised: Wallet Keys and Mnemonics StolenCritical supply-chain attack on Injective npm package exfiltrated wallet secrets.
EARLY WARNINGMAVENJULY 2026
Micronaut HTTP Client Vulnerability Under InvestigationReportedly, Micronaut HTTP Client lacks redirect limit, enabling DoS. Upgrade advised.
EARLY WARNINGNPMJULY 2026
Potential Open Redirect in Waku npm PackageReportedly, the `unstable_redirect()` helper in the `waku` npm package may lead to open redirect attacks.
EARLY WARNINGNPMJULY 2026
Open Redirect Vulnerability in waku npm PackageReportedly, the waku npm package has an open redirect vulnerability via unstable_redirect() helper.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
Nuclio <= 1.15.27 Vulnerability Under InvestigationNuclio <= 1.15.27 reportedly has a critical RCE vulnerability due to unsanitized inputs.
EARLY WARNINGWORDPRESSJULY 2026
Critical Vulnerability in Blocksy Companion Pro for WordPressReportedly critical unauthenticated arbitrary file upload vulnerability in Blocksy Companion Pro plugin for WordPress.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
oasdiff Vulnerability: SSRF and Local File Read Risksoasdiff versions <=v1.18.0 may be vulnerable to SSRF and local file read due to improper enforcement of external refs.
EARLY WARNINGGOJULY 2026
Goploy Package Vulnerability Under InvestigationReportedly, Goploy package allows unauthorized access and remote code execution.
EARLY WARNINGGOJULY 2026
Goploy Package Vulnerability: Cross-namespace IDOR and RCE RiskEarly warning of a high-severity vulnerability in the Goploy package that may lead to remote code execution.
EARLY WARNINGNPMJULY 2026
Critical Vulnerability in openmemory/api (CVE-2026-59705)An unauthenticated access vulnerability in openmemory/api allows arbitrary memory manipulation and denial-of-service.
EARLY WARNINGNPMJULY 2026
@better-auth/sso npm Package Vulnerability: Early WarningEarly warning of a potential server-side request forgery vulnerability in @better-auth/sso npm package.
EARLY WARNINGNPMJULY 2026
OAuth Provider Refresh Token Issue: Assess Your Exposure NowEarly warning: OAuth provider's refresh token mechanism under investigation. Learn how to assess your exposure.
EARLY WARNINGNPMJULY 2026
better-auth npm Package Vulnerability: OAuth Refresh Token IssueEarly warning: better-auth npm package has a vulnerability affecting oidcProvider and mcp plugins.
EARLY WARNINGNPMJULY 2026
Potential Phoenix Framework Presence Client VulnerabilityReportedly, a vulnerability in Phoenix Framework's Presence JavaScript client may cause client-side denial of service.
EARLY WARNINGPHPJULY 2026
Suspected China-Aligned Hackers Exploit Roundcube FlawsSuspected China-aligned threat cluster reportedly exploiting Roundcube webmail software at U.S. and Canadian universities.
CONFIRMEDNPMJULY 2026
Langflow Auth Bypass Vulnerability: CVE-2026-55255 Confirmed ExploitedLangflow contains a confirmed authorization bypass vulnerability allowing attackers to execute any flow. Upgrade to the latest version.
EARLY WARNINGCARGOJULY 2026
Critical Vulnerability in halo2_gadgets Affects ZebradReportedly, a critical vulnerability in halo2_gadgets could allow double-spending and fund theft. Monitor for updates.
EARLY WARNINGNPMJULY 2026
Decompress npm Package Vulnerability Under InvestigationReportedly, the @xhmikosr/decompress npm package has a vulnerability that may allow file creation outside the target directory.
EARLY WARNINGGITHUB-ACTIONSJULY 2026
Cilium Vulnerability: Sensitive Information Disclosure and Cluster DisruptionEarly warning: Cilium is reportedly vulnerable to sensitive information disclosure and cluster disruption.
EARLY WARNINGPYPIJULY 2026
Memory-Safety Vulnerability in Open Babel's MOPAC ParserReportedly, a memory-safety vulnerability in Open Babel's MOPAC output parser may allow out-of-bounds writes. Upgrade to Open Babel 3.2.0 or later.
EARLY WARNINGMAVENJULY 2026
Apache Camel Keycloak Component Vulnerability: Early WarningEarly warning of a high severity vulnerability in Apache Camel Keycloak Component. Assess your exposure now.
EARLY WARNINGMAVENJULY 2026
Apache Camel DNS Vulnerability: SSRF Risk Due to Improper Input ValidationEarly warning of a high severity vulnerability in Apache Camel DNS component leading to SSRF risk.
EARLY WARNINGMAVENJULY 2026
Apache Camel camel-mongodb-gridfs Vulnerability: Early WarningEarly warning of a potential vulnerability in Apache Camel's camel-mongodb-gridfs component. Upgrade recommended.
CONFIRMEDCARGOJULY 2026
Zebra <=v4.4.1: Critical Consensus Divergence Vulnerability ConfirmedZebra versions up to and including v4.4.1 have a critical consensus divergence vulnerability due to P2SH sigop undercount.
EARLY WARNINGCARGOJULY 2026
SurrealDB Vulnerability Under InvestigationSurrealDB vulnerability reportedly allows authenticated users to bypass permission restrictions.
CONFIRMEDNPMJUNE 2026
Critical IBM Langflow OSS Vulnerability: Upgrade or Restrict Redis AccessConfirmed critical vulnerability in IBM Langflow OSS 1.0.0 to 1.10.0 allows Redis users to execute arbitrary code.
EARLY WARNINGWORDPRESSJUNE 2026
ProfileGrid WordPress Plugin Under Investigation for Critical VulnerabilityProfileGrid WordPress plugin reportedly vulnerable to privilege escalation via account takeover.
EARLY WARNINGNPMJUNE 2026
Gorse <0.5.10 Authentication Bypass VulnerabilityGorse <0.5.10 reportedly contains a critical authentication bypass vulnerability. Upgrade to 0.5.10 or later.
CONFIRMEDLINUXJUNE 2026
Linux Kernel 'pedit COW' Flaw CVE-2026-46331: Urgent Patch RequiredHigh-severity Linux kernel flaw CVE-2026-46331 allows local unprivileged users to gain root access. Patch now.
EARLY WARNINGGOJUNE 2026
golang.org/x/crypto: Potential Server Deadlock on Unexpected ResponsesEarly warning: golang.org/x/crypto may cause server deadlock on unexpected responses. Upgrade recommended.
CONFIRMEDGOJUNE 2026
Gogs Path Traversal Vulnerability: Critical RCE Threat ConfirmedGogs has a confirmed path traversal vulnerability leading to RCE. Upgrade now.
EARLY WARNINGGOJUNE 2026
Gogs Path Traversal Vulnerability: Potential Remote Code ExecutionEarly warning: Gogs has a path traversal vulnerability in organization names that may lead to remote code execution.
CONFIRMEDGOJUNE 2026
Gogs Supply-Chain Threat: Multiple Vulnerabilities ConfirmedGogs package allows repo-write attackers to gain SSH footholds or RCE.
EARLY WARNINGGOJUNE 2026
Gogs Package Vulnerability: Potential Supply-Chain Attack RiskEarly warning of a Gogs package vulnerability that may allow symlink attacks.
EARLY WARNINGGOJUNE 2026
Gogs RCE Vulnerability via Pull Request Branch Name InjectionEarly warning: Gogs <0.15.0 reportedly allows RCE via pull request branch name injection.
EARLY WARNINGCISA_KEVJUNE 2026
Ubiquiti UniFi OS Vulnerability Under InvestigationReportedly, Ubiquiti UniFi OS has an improper input validation vulnerability allowing command injection.
CONFIRMEDCARGOJUNE 2026
Mise Package Vulnerability: Arbitrary Code Execution via Tera TemplatesMise package is vulnerable to arbitrary code execution through Tera templates in.tool-versions files.
EARLY WARNINGCARGOJUNE 2026
Mise Package Vulnerability: Arbitrary Code Execution via Tera TemplatesEarly warning: Mise package may allow arbitrary code execution via Tera templates in.tool-versions files.
CONFIRMEDPYPIJUNE 2026
Langflow IDOR Vulnerability Confirmed: Upgrade and Review Access ControlsLangflow package has a confirmed IDOR vulnerability allowing access to other users' flows.
EARLY WARNINGPYPIJUNE 2026
praisonai-platform PyPI Package: Default JWT Secret VulnerabilityEarly warning: praisonai-platform PyPI package reportedly has a default JWT signing secret that enables token forgery.
EARLY WARNINGPYPIJUNE 2026
praisonai-platform PyPI Package: Potential Hardcoded JWT Secret IssueEarly warning: praisonai-platform <= 0.1.4 may use a hardcoded JWT secret, enabling unauthenticated access.
EARLY WARNINGCISA_KEVJUNE 2026
Splunk Enterprise Vulnerability Under Investigation: Early WarningSplunk Enterprise reportedly contains a vulnerability that could allow unauthorized file creation or truncation.
CONFIRMEDGEMJUNE 2026
Avo Gem Critical Vulnerability: Missing Authorization Flaw ConfirmedAvo gem has a critical missing authorization flaw allowing privilege escalation and cross-tenant data exposure.
CONFIRMEDPYPIJUNE 2026
picklescan PyPI Package Unsafe Deserialization Vulnerability Confirmedpicklescan versions before 1.0.1 contain a high severity unsafe deserialization vulnerability allowing arbitrary code execution.
CONFIRMEDPYPIJUNE 2026
picklescan PyPI Package <= 0.0.32 Vulnerable: Upgrade Nowpicklescan package <= 0.0.32 has an arbitrary file writing vulnerability. Upgrade to 0.0.33 or later.
EARLY WARNINGGOJUNE 2026
rclone Package Vulnerability: Unauthenticated Command ExecutionEarly warning of a high severity vulnerability in rclone package allowing unauthenticated command execution.
EARLY WARNINGPYPIJUNE 2026
Multiple Vulnerabilities Reported in Crawl4AI Docker API ServerReportedly multiple critical vulnerabilities affect Crawl4AI Docker API server endpoints.
CONFIRMEDPYPIJUNE 2026
Critical Vulnerability in Crawl4AI Package: Sandbox Escape and RCEConfirmed critical vulnerability in Crawl4AI package allows sandbox escape and remote code execution.
EARLY WARNINGPYPIJUNE 2026
Crawl4AI Package Vulnerability: AST Sandbox Escape ThreatEarly warning on a potential vulnerability in the Crawl4AI package allowing sandbox escape and arbitrary code execution.
EARLY WARNINGPIPJUNE 2026
Potential Auth Bypass in vLLM Affecting OpenAI APIReportedly, a vulnerability in vLLM allows bypassing OpenAI API authentication. Upgrade to v0.14.1 or later.
EARLY WARNINGPHPJUNE 2026
LiteSpeed cPanel Plugin Flaw: Early Warning of Exploited VulnerabilityCISA warns of an actively exploited flaw in LiteSpeed cPanel Plugin, urging immediate action for affected users.
CONFIRMEDNPMJUNE 2026
remotion npm Package Arbitrary File Write Vulnerability Confirmedremotion npm package version v4.0.409 has an arbitrary file write vulnerability. Upgrade and review environments.
CONFIRMEDNPMJUNE 2026
V8 npm Package Vulnerability CVE-2026-11645: Update Chrome NowHigh-severity V8 npm package vulnerability CVE-2026-11645 is being actively exploited. Update Chrome to 149.0.7827.103 or later.
EARLY WARNINGCOMPOSERJUNE 2026
PHPSpreadsheet Patch Bypass Under InvestigationReportedly, PHPSpreadsheet has a bypass for CVE-2026-34084 patch, enabling remote code execution.
CONFIRMEDPYPIJUNE 2026
Microsoft durabletask PyPI Package Compromised: Critical Supply Chain ThreatThree malicious versions of Microsoft's durabletask Python SDK were published to PyPI, stealing credentials and spreading laterally.
EARLY WARNINGMAVENJUNE 2026
Apache Fory Java SDK Deserialization VulnerabilityReported deserialization flaw in Apache Fory Java SDK may allow bypass of security checks.
CONFIRMEDPYPIJUNE 2026
Jupyter Enterprise Gateway SSTI Vulnerability: Critical Threat ConfirmedConfirmed high severity threat in Jupyter Enterprise Gateway allows remote code execution via SSTI.
EARLY WARNINGGOMAY 2026
KubeVirt virt-handler Vulnerability Under InvestigationA flaw in KubeVirt's virt-handler component is under investigation. Users with edit permissions may be at risk.
EARLY WARNINGPYPIMAY 2026
MLflow <=3.10.1.dev0 Vulnerability: Unauthorized Access RiskMLflow <=3.10.1.dev0 may allow unauthorized access to multipart upload endpoints.
EARLY WARNINGGOMAY 2026
MCP Gateway: Potential Authority Injection and JWT BypassEarly warning: MCP Gateway may allow authority injection and JWT bypass via unauthenticated path.
EARLY WARNINGCOMPOSERMAY 2026
TYPO3 'Content Element Selector' Extension Under Investigation for RCETYPO3 'Content Element Selector' extension is reportedly vulnerable to Remote Code Execution via PHP Object Injection.
EARLY WARNINGGOMAY 2026
Crabbox Prior to v0.12.0: Environment Variable Exposure VulnerabilityEarly warning: Crabbox prior to v0.12.0 may expose local secrets via environment variables.
EARLY WARNINGGOMAY 2026
Portainer Endpoint Security Bypass Under InvestigationPortainer has an endpoint security bypass via Swarm service create/update. Review configurations.
EARLY WARNINGNPMMAY 2026
n8n npm Package Vulnerability: XML Node Patch Bypass Under InvestigationEarly warning: n8n npm package may have a critical vulnerability allowing RCE. Upgrade to mitigate.
EARLY WARNINGNPMMAY 2026
n8n npm Package Vulnerability: Potential Remote Code ExecutionEarly warning: n8n npm package has a vulnerability that could lead to remote code execution.
EARLY WARNINGNPMMAY 2026
Flowise npm Package RCE Vulnerability Under InvestigationFlowise npm package reportedly allows authenticated RCE via NodeVM sandbox escape.
EARLY WARNINGNPMMAY 2026
SandboxJS npm Package Sandbox Escape VulnerabilitySandboxJS npm package reportedly has a sandbox escape vulnerability due to Function.caller leakage.
EARLY WARNINGPYPIMAY 2026
PyTorch Lightning PyPI Package CompromisedReportedly, PyTorch Lightning PyPI package versions 2.6.2 and 2.6.3 have been compromised. Assess your exposure now.
EARLY WARNINGNPMAPRIL 2026
Fastify Header Stripping Vulnerability Under InvestigationFastify's connection header abuse may enable stripping of proxy-added headers, affecting @fastify/reply-from and @fastify/http-proxy users.
EARLY WARNINGGOAPRIL 2026
OAuth2 Proxy Authentication Bypass: Early WarningOAuth2 Proxy has an authentication bypass vulnerability via X-Forwarded-Uri header spoofing.
EARLY WARNINGNPMMARCH 2026
jsrsasign Package Vulnerability: Incomplete Comparison Threatjsrsasign versions from 7.0.0 to before 11.1.1 may allow private key recovery.
EARLY WARNINGPYPIFEBRUARY 2026
Critical Vulnerability in NLTK Downloader ComponentA critical vulnerability in NLTK downloader may allow arbitrary code execution. Upgrade to a patched version as soon as available.
EARLY WARNINGGOFEBRUARY 2026
Alist Application Vulnerable to MitM AttacksAlist application reportedly disables TLS verification by default, exposing it to MitM attacks.
EARLY WARNINGGOJANUARY 2026
Potential Scope Validation Bypass in Free5gc NRF 1.4.0An issue in Free5gc NRF 1.4.0 may allow scope validation bypass. Upgrade or patch.
EARLY WARNINGPYPIJANUARY 2026
Crawl4AI Docker API Vulnerable to Remote Code ExecutionReportedly, a critical remote code execution vulnerability exists in Crawl4AI Docker API. Upgrade to v0.8.0 or disable the API.
EARLY WARNINGPYPIDECEMBER 2025
Apache Airflow Providers Edge3 RCE VulnerabilityReportedly, Apache Airflow Providers Edge3 exposes an internal API allowing RCE. Assess your exposure now.
EARLY WARNINGMAVENSEPTEMBER 2025
Apache IoTDB Deserialization Vulnerability Under InvestigationApache IoTDB may have a high-severity deserialization flaw. Upgrade to 2.0.5 or restrict exposure.
EARLY WARNINGPYPIJUNE 2025
llama_index v0.12.21 Vulnerable to SQL Injection: Early WarningEarly warning: llama_index v0.12.21 has SQL injection vulnerabilities. Upgrade and review SQL usage.
EARLY WARNINGPYPIMARCH 2025
Potential SQL Injection in DuckDBRetriever: What You Need to KnowEarly warning: SQL injection vulnerability in DuckDBRetriever may allow RCE.

Join the waitlist →