2026-07-03
2026-07-03 21:16Z
CRIT

CVE-2026-26292 — Gitea: versions before 1.25.5 do not use the migration HTTP transport for LFS push

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26292

Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests. CVSSv3.1 9.8 (CRITICAL) · EPSS 7th percentile

CWECWE 284VNDGiteaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 21:16Z
CRIT

CVE-2026-26247 — Gitea: versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26247

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check. CVSSv3.1 9.1 (CRITICAL) · EPSS 6th percentile

CWECWE 284VNDGiteaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 21:16Z
CRIT

CVE-2026-26232 — Gitea: versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26232

Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange. CVSSv3.1 9.1 (CRITICAL) · EPSS 6th percentile

CWECWE 294VNDGiteaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 21:16Z
HIGH

CVE-2026-26231 — Gitea: versions up to and including 1.26.1 allow the Allow edits from maintainers permission

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26231

Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write. CVSSv3.1 8.5 (HIGH)

CWECWE 863VNDGiteaTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-03
2026-07-03 21:16Z
CRIT

CVE-2026-25718 — Gitea: versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25718

Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through symlinked or otherwise non-regular paths. CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

CWECWE 59VNDGiteaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 21:16Z
CRIT

CVE-2026-22874 — Gitea: versions up to and including 1.26.2 have incomplete SSRF protection in webhook and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22874

Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. CVSSv3.1 9.6 (CRITICAL)

CWECWE 918VNDGiteaTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-03
2026-07-03 21:16Z
HIGH

CVE-2026-22555 — Gitea: versions before 1.26.0 allow API users to fork a repository into an organization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22555

Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets. CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDGiteaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-03
2026-07-03 21:16Z
CRIT

CVE-2026-22547 — Gitea: versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22547

Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values. CVSSv3.1 9.1 (CRITICAL) · EPSS 6th percentile

CWECWE 20VNDGiteaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 21:16Z
CRIT

CVE-2026-20896 — Gitea: Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20896

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284VNDGiteaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 21:16Z
CRIT

CVE-2026-20706 — Gitea: versions up to and including 1.26.1 allow repository archive downloads to bypass token

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20706

Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint. CVSSv3.1 9.1 (CRITICAL) · EPSS 17th percentile

CWECWE 284VNDGiteaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 21:16Z
HIGH

CVE-2026-12481 — A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12481

A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the safe-mode guard when `safe_mode` is set to `None`, which is the default value when `from_config()` is called outside of a `SafeModeScope` context. This logic error conflates `None` (unset/default-deny) with `False` (explicitly disabled), by CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 15:16Z
HIGH

CVE-2026-14460 — Authorization: Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14460

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from <= 1.0.4 before 1.0.5. CVSSv3.1 8.8 (HIGH)

CWECWE 862TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 15:16Z
HIGH

CVE-2026-14459 — Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14459

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from <= 1.0.4 before 1.0.5. CVSSv3.1 8.8 (HIGH)

CWECWE 88TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 13:17Z
CRIT

CVE-2026-56015 — Net: Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56015

Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passes the prefix string to the trie builder addPrefixToTrie() without checking it against the address width. addPrefixToTrie() then walks the prefix buffer by prefix_length bits, reading prefix[byte] for byte up to prefix_len/8, where prefix is the 4-byte (IPv4) or 16-byte (IPv6) packed address. A prefix length greater than 32 for IPv4 or 128 for IPv6, for exam CVSSv3.1 9.1 (CRITICAL) · EPSS 13th percentile

CWECWE 125TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 11:16Z
HIGH

CVE-2026-10055 — Eclipse: In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10055

In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and returns the full response body to the caller. Because the destination URL is neither validated nor allowlisted, a remote attacker with access to the Theia service connection can issue server-side HTTP requests to localhost or other backend-reach CVSSv3.1 8.5 (HIGH)

CWECWE 918CWECWE 200VNDEclipseTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-03
2026-07-03 11:16Z
HIGH

CVE-2026-10054 — Eclipse: In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10054

In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal, /services/terminals/:id) without service-level authentication. WebSocket origin validation in @theia/core is fail-open: connections are accepted when the Origin header is missing or when no THEIA_HOSTS allowlist is configured (the default). The Socket.IO integration additionally replaces the real Origin header with a client CVSSv3.1 8.8 (HIGH)

CWECWE 306CWECWE 1385VNDEclipseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-03
2026-07-03 10:16Z
CRIT

CVE-2026-4321 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4321

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows SQL Injection. This issue affects Destekz: through 02062026. NOTE: The vendor was contacted and it was learned that the product is not supported. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 10:00Z
HIGH

Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign

Kaspersky Securelist·securelist.com

Kaspersky disclosed a phishing campaign by APT group Armored Likho (Eagle Werewolf) deploying BusySnake Stealer, a previously undocumented Python-based infostealer targeting Windows systems. The campaign uses spear-phishing with malicious archives containing NSIS droppers or LNK files exploiting ZDI-CAN-25373, leading to multi-stage payload delivery via GitHub-hosted repositories. BusySnake Stealer features PyArmor Pro obfuscation, credential harvesting from Firefox/Chromium browsers via DPAPI/NSS decryption, clipboard logging, screenshot capture, 2FA secret scraping, cryptocurrency wallet theft, Telegram session exfiltration, and reverse SSH tunneling via C2 commands.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFWebTACTA0003
78
Edit Score
2026-07-03
2026-07-03 08:16Z
CRIT

CVE-2026-47898 — Apache Lucene.net: Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47898

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue. CVSSv3.1 9.8 (CRITICAL) · EPSS 3th percentile

CWECWE 611VNDApacheTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 08:16Z
CRIT

CVE-2026-14544 — HPLIP: This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14544

A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190VNDHplipTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 07:16Z
CRIT

CVE-2026-9079 — libcurl had a flaw that when instructed to clear proxy authentication credentials which made

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9079

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them. CVSSv3.1 9.8 (CRITICAL) · EPSS 16th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 07:16Z
CRIT

CVE-2026-8927 — When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8927

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`. CVSSv3.1 9.1 (CRITICAL) · EPSS 16th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 07:16Z
CRIT

CVE-2026-8926 — When asking curl to use a `.netrc` file to find credentials and at the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8926

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user. CVSSv3.1 9.1 (CRITICAL) · EPSS 9th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-03
2026-07-03 07:16Z
CRIT

CVE-2026-8925 — The curl logic that works with SASL authentication could end up cleaning up the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8925

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice. CVSSv3.1 9.8 (CRITICAL) · EPSS 16th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-03
2026-07-03 07:16Z
CRIT

CVE-2026-8924 — A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8924

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. CVSSv3.1 9.1 (CRITICAL) · EPSS 12th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score