2026-06-22
2026-06-22 23:16Z
HIGH

CVE-2026-54232 — Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54232

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through the flashinfer-jit-cache package. The package is installed from a custom index (flashinfer.ai/whl/) using --extra-index-url, but the package name was not registered on PyPI, and UV_INDEX_STRATEGY="unsafe-best-match" is set globally. An attacker who registers flashinfer-jit-cache on PyPI with version 0.6.11.post2 CVSSv3.1 8.8 (HIGH)

CWECWE 427TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-22
2026-06-22 23:16Z
CRIT

CVE-2026-48746 — From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48746

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0. CVSSv3.1 9.1 (CRITICAL)

CWECWE 444TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-22
2026-06-22 22:16Z
CRIT

CVE-2026-56348 — n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56348

n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential access can cause the n8n server to issue HTTP requests with credentials to unauthorized hosts, exfiltrating sensitive authentication data. CVSSv3.1 9.1 (CRITICAL)

CWECWE 918TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-22
2026-06-22 22:16Z
HIGH

CVE-2026-56324 — Capgo: before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56324

Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to circumvent rate limiting by rotating the user-controlled device_id parameter. Attackers can send multiple requests per second by changing device_id values to flood the channel_devices table and cause database exhaustion. CVSSv3.1 8.2 (HIGH)

CWECWE 770VNDCapgoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 22:16Z
HIGH

CVE-2026-56266 — Crawl4AI: Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4 addresses to reach internal

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56266

Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4 addresses to reach internal services and cloud metadata endpoints. CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDCrawl4aiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-22
2026-06-22 22:16Z
CRIT

CVE-2026-48509 — Messagepack Messagepack: This insecure default can expose applications to denial-of-service attacks that MessagePackSecurity.UntrustedData is intended to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48509

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which resolve to MessagePackSerializerOptions.Standard with MessagePackSecurity.TrustedData. The formatter is designed for ASP.NET Core MVC request bodies, which commonly cross an HTTP trust boundary. This insecure default can expose applications to denial-of-service attacks that MessagePackSecurity.Untru CVSSv3.1 9.1 (CRITICAL)

CWECWE 1188VNDMessagepackTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-22
2026-06-22 22:16Z
HIGH

CVE-2026-48109 — MessagePack: A remote attacker can send a crafted MessagePack payload with manipulated LZ4 token/length fields

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48109

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes Lz4Block and Lz4BlockArray. The decoder implementation is based on a deprecated fast-decompression algorithm that does not take a source-length bound. A remote attacker can send a crafted MessagePack payload with manipulated LZ4 token/length fields to force out-of-bounds reads from the compressed CVSSv3.1 8.2 (HIGH)

CWECWE 20VNDMessagepackTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-22
2026-06-22 22:16Z
HIGH

CVE-2025-71358 — picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.AutoComplete.get_entity function in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71358

picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.AutoComplete.get_entity function in reduce methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when loaded by victims using pickle.load(). CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 22:16Z
HIGH

CVE-2025-71344 — picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71344

picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function when scanning pickle files, allowing attackers to execute arbitrary code. Malicious pickle files embedding ensurepip._run_pip calls in __reduce__ methods bypass picklescan detection and achieve remote code execution upon pickle.load() invocation. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 22:16Z
HIGH

CVE-2025-71339 — Picklescan: before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, allowing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71339

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded by victims who trust Picklescan's safety validation. CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDPicklescanTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 21:16Z
CRIT

CVE-2026-49468 — Litellm Litellm: Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49468

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effective route from request.url.path in litellm/proxy/auth/auth_utils.py::get_request_route(), which Starlette reconstructs from the Host header. A crafted Host could therefore make the auth gate evaluate a CVSSv3.1 9.8 (CRITICAL) · EPSS 42th percentile

CWECWE 290VNDLitellmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-22
2026-06-22 20:16Z
HIGH

CVE-2026-44272 — Dell: Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44272

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-22
2026-06-22 20:16Z
HIGH

CVE-2026-44271 — Dell: Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44271

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDDellTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 18:16Z
HIGH

CVE-2026-55602 — Chimurai Http-proxy-middleware: is node.js http-proxy middleware.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55602

http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request metadata. As a result, a crafted Host header that is only a superstring match for a configured host+path key can still route a request to an unintended backend. This vulnerability is CVSSv3.1 8.6 (HIGH) · EPSS 31th percentile

CWECWE 20CWECWE 187VNDChimuraiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-22
2026-06-22 18:16Z
HIGH

CVE-2026-55388 — piscina is a node.js worker pool implementation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55388

piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() paths read the filename option via plain member access. Both reads fall through the prototype chain when the caller's options object doesn't have filename as an own property. When Object.prototype.filename is polluted upstream the inherited value flows to worker_threads.Worker import and the attacker's .mjs runs in the worker. This vulnerability is fixed in CVSSv3.1 8.1 (HIGH)

CWECWE 94CWECWE 1321TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 18:16Z
HIGH

CVE-2026-54271 — This is a bypass of CVE-2026-44295.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54271

protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name handling in pbjs static / static-module code generation was incomplete. Affected versions of protobufjs-cli could still emit unsafe JavaScript references when generating static output from crafted JSON descriptor input. The common case of parsing schemas from .proto files is not affected. This is a bypass of CVE-2026-44295. An attacker who can provide or influen CVSSv3.1 8.2 (HIGH)

CWECWE 94TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 18:16Z
HIGH

CVE-2026-50168 — Angular Angular: Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/platform-server package allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50168

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/platform-server package allows remote attackers to bypass host allowlist constraints and direct server-side outgoing requests to arbitrary external endpoints. This occurs due to a parser differential between the strict WHATWG URL parser used for allowlist validation and CVSSv3.1 8.2 (HIGH) · EPSS 9th percentile

CWECWE 918CWECWE 346VNDAngularTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 18:16Z
CRIT

CVE-2026-12249 — Canonical: Because the system automatically accepts this certificate and registers it into the local system

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12249

An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py), ADSys utilizes a plaintext HTTP connection (http://) instead of a secure HTTPS connection (https://) to request the CA certificate from the Active Directory Certificate Services server (GetCACert). An CVSSv3.1 9.0 (CRITICAL)

CWECWE 348VNDCanonicalTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-06-22
2026-06-22 18:16Z
CRIT

CVE-2026-10789 — A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10789

A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user. CVSSv3.1 9.6 (CRITICAL)

CWECWE 94TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-22
2026-06-22 16:50Z
HIGH

Introducing Patch the Planet

Trail of Bits·blog.trailofbits.com

Trail of Bits launched Patch the Planet, a coordinated initiative pairing security engineers with open-source maintainers to systematically discover and fix vulnerabilities across critical projects using frontier AI models like GPT-5.5-Cyber. In the first week, the effort produced 64 pull requests, 51 filed issues, and 37 merged patches across 19 projects including cURL, Python, PyCA, Sigstore, and RustCrypto, with over 30 projects now enrolled. The initiative demonstrates that AI-driven vulnerability discovery at scale has shifted the bottleneck from finding bugs to triaging, patching, and coordinating disclosure—and provides maintainers with practical guidance (AGENTS.md, threat models, severity criteria) to filter AI-generated noise.

SRFApplicationSRFSupply ChainSWZizmorSWAiohttpSWCurlSWFreenginxSWNatsSWPyca
82
Edit Score
2026-06-22
2026-06-22 16:16Z
HIGH

CVE-2026-9072 — IBM: i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9072

IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in. CVSSv3.1 8.1 (HIGH)

CWECWE 94VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 16:16Z
CRIT

CVE-2026-7664 — IBM: Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7664

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-22
2026-06-22 16:16Z
HIGH

CVE-2026-56104 — Chainlit: before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56104

Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSocket session restoration without ownership verification. Attackers can exploit the restore_existing_session path to assume a victim's permissions and roles, enabling unauthorized invocation of tools and access to data restricted to the authenticated victim. CVSSv3.1 8.2 (HIGH) · EPSS 17th percentile

CWECWE 862VNDChainlitTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-22
2026-06-22 16:16Z
HIGH

CVE-2026-50178 — Angular Angular_language_service: This setting instructs VS Code to trust all rendered content it receives, which enables

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50178

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS Code extension configures the tooltip Markdown renderer with the isTrusted: true option (located in client/src/client.ts). This setting instructs VS Code to trust all rendered content it receives, which enables active elements such as command: URIs. However, the background Angular Language Server process fails to escape or saniti CVSSv3.1 8.8 (HIGH) · EPSS 17th percentile

CWECWE 94CWECWE 79VNDAngularTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-22
2026-06-22 16:16Z
HIGH

CVE-2026-49241 — Angular Angular_language_service: The Angular Language Service VS Code Extension provides a rich editing experience for Angular

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49241

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Language Service VS Code extension reads the custom TypeScript SDK paths typescript.tsdk and js/ts.tsdk.path directly from workspace configurations (.vscode/settings.json) without verifying VS Code Workspace Trust state or asking for user consent (located in client/src/client.ts). The client-side extension then passes the parsed set CVSSv3.1 8.8 (HIGH) · EPSS 8th percentile

CWECWE 94CWECWE 79CWECWE 427CWECWE 494VNDAngularTYPVulnerability
8.8
CVSS v3.1
94
Edit Score