2026-06-10
2026-06-10 23:16Z
CRIT

CVE-2026-46703 — Boxlite: Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46703

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in OCI images, Boxlite does not account for the possibility that entries may be symlinks pointing to absolute paths. An attacker can craft a malicious OCI image and distribute it on i CVSSv3.1 9.6 (CRITICAL)

CWECWE 22VNDBoxliteTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-10
2026-06-10 23:16Z
CRIT

CVE-2026-46695 — Boxlite: This allows malicious code to perform arbitrary write operations on directories that should be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46695

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capabilities available inside the container, malicious code can remount the directory in rw mode, thereby gaining write access to that directory. This allows malicious code to perform arbitrary write operations on directories that should be read-only. This issue h CVSSv3.1 10.0 (CRITICAL)

CWECWE 284VNDBoxliteTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-10
2026-06-10 23:16Z
HIGH

CVE-2026-44693 — FTL: Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability in the HTTP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44693

Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability in the HTTP session management subsystem, introduced with the v6.0 rewrite of the embedded CivetWeb-based web server. This issue has been patched in version 6.6.1. CVSSv3.1 8.8 (HIGH)

CWECWE 362VNDFtlTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 23:16Z
HIGH

CVE-2026-42305 — Dulwich: Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42305

Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when cloning or checking out a malicious Git repository on Windows. Dulwich's path-element validator accepted tree entries whose filenames contained bytes that Windows interprets as structural path syntax. Contributing configuration bugs made matters worse. The core.protectNTFS and core.pr CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDDulwichTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 22:17Z
HIGH

CVE-2026-53738 — Copy: & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53738

Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDCopyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 22:17Z
HIGH

CVE-2026-50131 — Fedify: previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validation before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50131

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validation before runtime document and media fetching. However, the IPv4 validation logic present starting in version 0.11.2 and prior to versions 1.9.12, 1.10.11, 2.0.19, 2.1.15, and 2.2.4 appears incomplete. The `validatePublicUrl()` protection relies on `isValidPublicIPv4Address()` to CVSSv3.1 8.6 (HIGH)

CWECWE 918CWECWE 1286CWECWE 1389VNDFedifyTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-10
2026-06-10 22:16Z
CRIT

CVE-2026-0274 — Paloaltonetworks Cortex_xsiam_commvaultsecurityiq_marketplace: An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0274

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources. CVSSv3.1 9.1 (CRITICAL) · EPSS 23th percentile

CWECWE 1390VNDPaloaltonetworksTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-10
2026-06-10 20:17Z
HIGH

CVE-2026-6893 — These options are improperly handled and written into temporary shell scripts without proper escaping

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6893

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentiall CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 19:16Z
CRIT

CVE-2026-50638 — Metrics: The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50638

Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by newlines, to be sent per packet. Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter::Statsd, which has a similar vulnerability. In addition, the _tags function does not check tags for newlines or statsd control characters. The tags can be used for metric injecti CVSSv3.1 9.1 (CRITICAL)

CWECWE 93VNDMetricsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-10
2026-06-10 19:16Z
HIGH

CVE-2026-50637 — Metrics: The statsd protocol (and extensions) allow mutiple metrics,separated by newlines, to be sent per

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50637

Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics,separated by newlines, to be sent per packet. The send method does not validate the contents of the metric names or values. If the names have newlines and statsd control characters (colon, pipe) then metric injections are possible. Version 0.04 fixed this by modifying the _make method to block metric names with c CVSSv3.1 8.2 (HIGH)

CWECWE 93VNDMetricsTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 18:17Z
HIGH

CVE-2026-50570 — Fission: Prior to version 1.25.0, Fission added PodSpec safety validation for tenant-facing Environment and Function

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50570

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Fission added PodSpec safety validation for tenant-facing Environment and Function CRDs (ValidatePodSpecSafety / ValidateContainerSafety admission webhook + sanitizeContainerSecurityContext executor merge layer), but the capability check was implemented as a fixed denylist of six Linux capabilities (SYS_ADMIN, N CVSSv3.1 8.5 (HIGH)

CWECWE 269CWECWE 732VNDFissionTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-10
2026-06-10 18:17Z
CRIT

CVE-2026-50566 — Fission: Prior to version 1.24.0, a tenant with environments.fission.io create/update RBAC can run privileged /

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50566

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a tenant with environments.fission.io create/update RBAC can run privileged / allowPrivilegeEscalation / dangerous-capability containers in the Fission function or builder namespace, scheduled under the executor's high-privilege service account — enabling container-sandbox escape, host filesystem and network acc CVSSv3.1 9.9 (CRITICAL)

CWECWE 269CWECWE 250VNDFissionTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-10
2026-06-10 18:17Z
CRIT

CVE-2026-50564 — Fission: Prior to version 1.24.0, Fission's Environment CRD exposes spec.runtime.podSpec and spec.builder.podSpec, which are merged

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50564

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Environment CRD exposes spec.runtime.podSpec and spec.builder.podSpec, which are merged into the Kubernetes pod specs for runtime and builder pods. The merge logic propagated hostNetwork, hostPID, hostIPC, container privileged, and serviceAccountName from the user-supplied podspec with no filtering, an CVSSv3.1 9.9 (CRITICAL)

CWECWE 269CWECWE 284CWECWE 693VNDFissionTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-10
2026-06-10 18:17Z
CRIT

CVE-2026-50563 — Fission: Prior to version 1.24.0, Fission's Container Executor path lets a tenant supply Function.spec.podspec directly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50563

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Container Executor path lets a tenant supply Function.spec.podspec directly; the executor merges it into the executor-built podspec and creates a Deployment whose pods run the user's container image. This issue has been patched in version 1.24.0. CVSSv3.1 9.9 (CRITICAL)

CWECWE 269CWECWE 284VNDFissionTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-10
2026-06-10 18:17Z
CRIT

CVE-2026-50545 — Fission: Prior to version 1.24.0, the Environment.spec.runtime.podSpec / spec.builder.podSpec passthrough lacked validation, and MergePodSpec propagated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50545

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Environment.spec.runtime.podSpec / spec.builder.podSpec passthrough lacked validation, and MergePodSpec propagated dangerous fields into the generated pods. This issue has been patched in version 1.24.0. CVSSv3.1 9.9 (CRITICAL)

CWECWE 269CWECWE 284CWECWE 693VNDFissionTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-10
2026-06-10 18:17Z
HIGH

CVE-2026-49824 — Fission: Prior to version 1.24.0, the Fission Function admission webhook (pkg/webhook/function.go) validated that spec.secrets[].namespace and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49824

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Fission Function admission webhook (pkg/webhook/function.go) validated that spec.secrets[].namespace and spec.configmaps[].namespace equalled the function's own namespace but performed no equivalent check on spec.environment.namespace. This issue has been patched in version 1.24.0. CVSSv3.1 8.5 (HIGH)

CWECWE 284CWECWE 863VNDFissionTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-10
2026-06-10 18:17Z
CRIT

CVE-2026-46614 — Fission: The route was mounted on the same listener as user-defined HTTPTriggers (svc/router, port 8888)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46614

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission router registers an internal-style route — /fission-function/<name> and /fission-function/<ns>/<name> — for every Function object, independent of whether any HTTPTrigger exists for that function. The route was mounted on the same listener as user-defined HTTPTriggers (svc/router, port 8888), so any c CVSSv3.1 9.8 (CRITICAL)

CWECWE 862CWECWE 284VNDFissionTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-10
2026-06-10 18:17Z
HIGH

CVE-2026-46612 — Fission: Prior to version 1.23.0, the Fission storagesvc component registers archive CRUD handlers (/v1/archive GET

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46612

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission storagesvc component registers archive CRUD handlers (/v1/archive GET / POST / DELETE and /v1/archives list) directly on its HTTP router without performing any authentication or authorization. Any caller able to reach the storagesvc ClusterIP — including any other workload in the same Kubernetes clus CVSSv3.1 8.8 (HIGH)

CWECWE 306VNDFissionTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 18:16Z
HIGH

CVE-2026-45062 — FrankenPHP: In any deployment where the attacker can place content into a file served by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45062

FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead FrankenPHP into treating a non-.php file as a .php script. In any deployment where the attacker can place content into a file served by FrankenPHP (uploads, file storage, etc.), this c CVSSv3.1 8.1 (HIGH)

CWECWE 20CWECWE 178CWECWE 176VNDFrankenphpTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 18:16Z
CRIT

CVE-2026-20253 — Splunk: In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20253

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDSplunkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-10
2026-06-10 18:16Z
HIGH

CVE-2026-20251 — Splunk: In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20251

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.<br><br>The Remote Code Execution is possible because of unsafe deserialization of CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDSplunkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 16:17Z
HIGH

CVE-2026-49759 — Erlang Erlang\/otp: Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49759

Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a si CVSSv3.1 8.2 (HIGH) · EPSS 27th percentile

CWECWE 121VNDErlangVNDStackTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 16:17Z
HIGH

CVE-2026-46558 — Plane: Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46558

Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces. This issue has been patched in version 1.3.1. CVSSv3.1 8.3 (HIGH)

CWECWE 862CWECWE 639VNDPlaneTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-10
2026-06-10 16:17Z
HIGH

CVE-2026-45569 — Roxy: In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block ..

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45569

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in app/modules/config/config.py:462. This is tuple-membership, not substring containment — '..' in (a, b, c) evaluates to True only if any of a, b, c is equal to the literal string '..'. For any realistic path-traversal payload (../../etc/passw CVSSv3.1 8.1 (HIGH)

CWECWE 22CWECWE 697VNDRoxyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-10
2026-06-10 16:17Z
HIGH

CVE-2026-45567 — Roxy: In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45567

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publication, there are no publicly available patches. CVSSv3.1 8.3 (HIGH)

CWECWE 306CWECWE 287CWECWE 697VNDRoxyTYPVulnerability
8.3
CVSS v3.1
92
Edit Score