2026-05-27
2026-05-27 17:16Z
CRIT

CVE-2026-44329 — free5GC is an open-source implementation of the 5G core network.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44329

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization middleware. A network attacker who can reach SMF on the SBI can hit UPI endpoints with no Authorization header at all, and the requests reach the SMF business handlers. In the running Docker lab this was directly demonstrated for read (GET /upi/v1/upNodesLinks), write (POST /upi/v1/upNodesLinks with atta CVSSv3.1 10.0 (CRITICAL)

CWECWE 862CWECWE 306TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-27
2026-05-27 17:16Z
HIGH

CVE-2026-44328 — This is an unauthenticated, state-mutating panic-DoS sink that an off-path network attacker can trigger

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44328

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. On top of that, the DELETE /upi/v1/upNodesLinks/{upNodeRef} handler unconditionally dereferences upNode.UPF after the type-guarded async release, even though AN-typed nodes are constructed without a UPF object. As a result, a single unauthenticated DELETE /upi/v1/upNodesLinks/gNB1 request crashes the handler wi CVSSv3.1 8.2 (HIGH)

CWECWE 862CWECWE 306CWECWE 476TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 17:16Z
CRIT

CVE-2026-44327 — free5GC is an open-source implementation of the 5G core network.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44327

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route with no Authorization header at all and the handler returns 200 OK. The current OAM handler is a stub that returns null, but the structural defect is route-group-scoped: the entire OAM route group has no inbound auth middleware, so CVSSv3.1 10.0 (CRITICAL)

CWECWE 862CWECWE 306TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-27
2026-05-27 17:16Z
CRIT

CVE-2026-44326 — free5GC is an open-source implementation of the 5G core network.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44326

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, read, patch, and delete traffic-influence subscriptions either with no Authorization header at all, or with a forged bearer token (e.g. Authorization: Bearer not-a-real-token). This includes creating AnyUeInd=true subscriptions intended CVSSv3.1 9.4 (CRITICAL)

CWECWE 862TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-05-27
2026-05-27 17:16Z
CRIT

CVE-2026-44315 — free5GC is an open-source implementation of the 5G core network.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44315

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, read, and delete PFD-management transaction state with a forged or arbitrary bearer token (e.g. Authorization: Bearer not-a-real-token). The route group is also reachable even when the running config's ServiceList does not declare it, so o CVSSv3.1 9.4 (CRITICAL)

CWECWE 862TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-05-27
2026-05-27 17:16Z
HIGH

CVE-2026-42790 — Erlang Erlang\/otp: Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42790

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. Two flaws combine to allow a subordinate CA whose DNS nameConstraints are restricted (e.g. permitted;DNS:allowed.example.com) to issue a leaf certificate that an OTP TLS client accepts as a valid identity for an out-of-scope hostname (e.g. victim.example.com): First, pubk CVSSv3.1 8.1 (HIGH)

CWECWE 295CWECWE 297VNDErlangTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 17:16Z
HIGH

CVE-2026-42083 — Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42083

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI. In NewServer(), the smPolicyGroup route group is created and routes are applied without attaching the router authorization middleware. In contrast, other PCF service groups such as Npcf_PolicyAuthorization do attach RouterAuthorizationCheck before route CVSSv3.1 8.2 (HIGH)

CWECWE 862TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-27
2026-05-27 15:16Z
HIGH

CVE-2026-6957 — Mattermost: Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6957

Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of a remote federated Mattermost server to write files to arbitrary locations within the target server's filestore via a malicious filename delivered through the shared-channel attachment sync protocol. Mattermost Advisory ID: MMSA-2026-00659 CVSSv3.1 8.0 (HIGH)

CWECWE 22VNDMattermostTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-27
2026-05-27 15:16Z
HIGH

CVE-2026-49046 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49046

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Duplicate Page and Post allows Blind SQL Injection. This issue affects Duplicate Page and Post: from n/a through 2.9.5. CVSSv3.1 8.5 (HIGH)

CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-27
2026-05-27 15:16Z
HIGH

CVE-2026-48920 — Jenkins: Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48920

Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem. CVSSv3.1 8.8 (HIGH)

CWECWE 73VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 15:16Z
CRIT

CVE-2026-45570 — Go-git_project Go-git: is an extensible git implementation library written in pure Go.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45570

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path containing a single quote can therefore break out of the quoted region in the exec command and be appended as additional shell tokens. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4. CVSSv3.1 9.6 (CRITICAL) · EPSS 5th percentile

CWECWE 116VNDGo Git ProjectTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-27
2026-05-27 15:16Z
HIGH

CVE-2026-44988 — LibVNCClient: In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44988

LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for the Gradient filter, but it does not reject Tight rectangles whose width is larger than 2048 pixels. A malicious VNC server can send a crafted FramebufferUpdate rectangle using Tight encoding with NoZlib | ExplicitFilter and the Gradient filter. When a LibVNCClient-based client connects, the client proce CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDLibvncclientTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 15:16Z
HIGH

CVE-2026-44971 — GuardDog: This allows an attacker who can influence the scanned repository URL to trigger SSRF

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44971

GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replacement and then sends the caller's GitHub credentials with the resulting request. This allows an attacker who can influence the scanned repository URL to trigger SSRF and capture the GH_TOKEN used by GuardDog. This vulnerability is fixed in . CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDGuarddogTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 15:16Z
HIGH

CVE-2026-44838 — Broadcom Rabbitmq_server: From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44838

RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrators can create patterns such as ^{client_id}-sensors$ to restrict user access to topics that include their client ID. However, the client_id is provided by the user in the MQTT CONNECT packet and is inserted into the regex pattern without escaping special regex characters. This fl CVSSv3.1 8.1 (HIGH) · EPSS 14th percentile

CWECWE 863VNDBroadcomVNDRabbitmqTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 15:16Z
HIGH

CVE-2026-42184 — Tauri Tauri: From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42184

Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On these systems, Tauri maps custom URI scheme protocols to http://<scheme>.localhost/ because those platforms' WebView implementations cannot serve custom URI schemes directly. The issue is that Tauri's check to see if the origin is local, only c CVSSv3.1 8.8 (HIGH)

CWECWE 918VNDTauriTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 14:17Z
HIGH

CVE-2026-8179 — IBM: Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8179

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could allow an authenticated user to execute arbitrary code on the system. CVSSv3.1 8.8 (HIGH)

CWECWE 121VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 14:17Z
CRIT

CVE-2026-8175 — IBM: Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8175

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a denial of service and potentially lead to authentication bypass or remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-27
2026-05-27 14:17Z
CRIT

CVE-2026-7876 — IBM: Aspera HSTS for CP4I 1.5.1 through 1.5.19

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7876

IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 CVSSv3.1 9.1 (CRITICAL)

CWECWE 287VNDIbmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-27
2026-05-27 14:17Z
CRIT

CVE-2026-7524 — IBM: Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7524

IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-27
2026-05-27 14:17Z
HIGH

CVE-2026-7365 — IBM: Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7365

IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication. CVSSv3.1 8.4 (HIGH)

CWECWE 1392VNDIbmTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-27
2026-05-27 14:17Z
HIGH

CVE-2026-5065 — IBM: Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5065

IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. CVSSv3.1 8.8 (HIGH)

CWECWE 798VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 14:17Z
HIGH

CVE-2026-46099 — Linux: Simplified race sequence: ksoftirqd/X higher-prio task (same CPU X) ----------- -------------------------------- seg6_input_core(,skb)/rpl_input(skb) dst_cache_get() ->

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46099

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels seg6_input_core() and rpl_input() call ip6_route_input() which sets a NOREF dst on the skb, then pass it to dst_cache_set_ip6() invoking dst_hold() unconditionally. On PREEMPT_RT, ksoftirqd is preemptible and a higher-priority task can release the underlying pcpu_rt between the lookup and the caching through a concurrent FIB lookup on a shared nexthop. CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 14:17Z
HIGH

CVE-2026-46056 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46056

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers hci_conn lookup and field access must be covered by hdev lock in hci_user_passkey_notify_evt() and hci_keypress_notify_evt(), otherwise the connection can be freed concurrently. Extend the hci_dev_lock critical section to cover all conn usage in both handlers. Keep the existing keypress notification behavior unchanged by routing the early exi CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 14:17Z
CRIT

CVE-2026-46043 — Linux: In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate pad and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46043

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv rxe_rcv() currently checks only that the incoming packet is at least header_size(pkt) bytes long before payload_size() is used. However, payload_size() subtracts both the attacker-controlled BTH pad field and RXE_ICRC_SIZE from pkt->paylen: payload_size = pkt->paylen - offset[RXE_PAYLOAD] - bth_pad(pkt) - RXE_ICRC_SIZE Th CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-27
2026-05-27 14:17Z
CRIT

CVE-2026-46039 — Linux: In the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46039

In the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer overflow in length check Fix potential integer overflow in rxgk_extract_token() when checking the length of the ticket. Rather than rounding up the value to be tested (which might overflow), round down the size of the available data. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score