2026-05-08
2026-05-08 15:16Z
HIGH

CVE-2026-43452 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: guard option

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43452

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: guard option walkers against 1-byte tail reads When the last byte of options is a non-single-byte option kind, walkers that advance with i += op[i + 1] ? : 1 can read op[i + 1] past the end of the option area. Add an explicit i == optlen - 1 check before dereferencing op[i + 1] in xt_tcpudp and xt_dccp option walkers. CVSSv3.1 8.2 (HIGH)

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-08
2026-05-08 15:16Z
CRIT

CVE-2026-43414 — Linux: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43414

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix fcport double free In qla24xx_els_dcmd_iocb() sp->free is set to qla2x00_els_dcmd_sp_free(). When an error happens, this function is called by qla2x00_sp_release(), when kref_put() releases the first and the last reference. qla2x00_els_dcmd_sp_free() frees fcport by calling qla2x00_free_fcport(). Doing it one more time after kref_put() is a bad idea. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-08
2026-05-08 15:16Z
CRIT

CVE-2026-43407 — Linux: In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43407

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() This patch fixes an out-of-bounds access in ceph_handle_auth_reply() that can be triggered by a message of type CEPH_MSG_AUTH_REPLY. In ceph_handle_auth_reply(), the value of the payload_len field of such a message is stored in a variable of type int. A value greater than INT_MAX leads to an integer overflow and is interpreted as a nega CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-08
2026-05-08 15:16Z
CRIT

CVE-2026-43406 — Linux: In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43406

In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in process_message_header() If the message frame is (maliciously) corrupted in a way that the length of the control segment ends up being less than the size of the message header or a different frame is made to look like a message frame, out-of-bounds reads may ensue in process_message_header(). Perform an explicit bounds check before decoding the message head CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-08
2026-05-08 15:16Z
HIGH

CVE-2026-43403 — Linux: In the Linux kernel, the following vulnerability has been resolved: nsfs: tighten permission checks

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43403

In the Linux kernel, the following vulnerability has been resolved: nsfs: tighten permission checks for ns iteration ioctls Even privileged services should not necessarily be able to see other privileged service's namespaces so they can't leak information to each other. Use may_see_all_namespaces() helper that centralizes this policy until the nstree adapts. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-08
2026-05-08 15:16Z
CRIT

CVE-2026-43402 — Linux: In the Linux kernel, the following vulnerability has been resolved: kthread: consolidate kthread exit

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43402

In the Linux kernel, the following vulnerability has been resolved: kthread: consolidate kthread exit paths to prevent use-after-free Guillaume reported crashes via corrupted RCU callback function pointers during KUnit testing. The crash was traced back to the pidfs rhashtable conversion which replaced the 24-byte rb_node with an 8-byte rhash_head in struct pid, shrinking it from 160 to 144 bytes. struct kthread (without CONFIG_BLK_CGROUP) is also 144 bytes. With CONFIG_SL CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-08
2026-05-08 15:16Z
HIGH

CVE-2026-43391 — Linux: In the Linux kernel, the following vulnerability has been resolved: nsfs: tighten permission checks

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43391

In the Linux kernel, the following vulnerability has been resolved: nsfs: tighten permission checks for handle opening Even privileged services should not necessarily be able to see other privileged service's namespaces so they can't leak information to each other. Use may_see_all_namespaces() helper that centralizes this policy until the nstree adapts. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-08
2026-05-08 15:16Z
CRIT

CVE-2026-43384 — Linux: In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43384

In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-08
2026-05-08 15:16Z
CRIT

CVE-2026-43383 — Linux: In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43383

In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this. CVSSv3.1 9.4 (CRITICAL)

TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-05-08
2026-05-08 15:16Z
CRIT

CVE-2026-43379 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43379

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close() opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is being accessed after rcu_read_unlock() has been called. This creates a race condition where the memory could be freed by a concurrent writer between the unlock and the subsequent pointer dereferences (opinfo->is_lease, etc.), leading to a use-after-free. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-08
2026-05-08 15:16Z
CRIT

CVE-2026-43378 — Linux Linux_kernel: In the Linux kernel, the following vulnerability has been resolved: smb: server: fix use-after-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43378

In the Linux kernel, the following vulnerability has been resolved: smb: server: fix use-after-free in smb2_open() The opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is dereferenced after rcu_read_unlock(), creating a use-after-free window. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-08
2026-05-08 15:16Z
HIGH

CVE-2026-43377 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: Don't log keys

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43377

In the Linux kernel, the following vulnerability has been resolved: ksmbd: Don't log keys in SMB3 signing and encryption key generation When KSMBD_DEBUG_AUTH logging is enabled, generate_smb3signingkey() and generate_smb3encryptionkey() log the session, signing, encryption, and decryption key bytes. Remove the logs to avoid exposing credentials. CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-08
2026-05-08 15:16Z
CRIT

CVE-2026-43376 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43376

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free by using call_rcu() for oplock_info ksmbd currently frees oplock_info immediately using kfree(), even though it is accessed under RCU read-side critical sections in places like opinfo_get() and proc_show_files(). Since there is no RCU grace period delay between nullifying the pointer and freeing the memory, a reader can still access oplock_info structure after it has been freed. T CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-08
2026-05-08 15:16Z
HIGH

CVE-2026-43365 — Linux: This leads to corrupt logs and unmountable filesystems in generic/617 on a disk with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43365

In the Linux kernel, the following vulnerability has been resolved: xfs: fix undersized l_iclog_roundoff values If the superblock doesn't list a log stripe unit, we set the incore log roundoff value to 512. This leads to corrupt logs and unmountable filesystems in generic/617 on a disk with 4k physical sectors... XFS (sda1): Mounting V5 Filesystem ff3121ca-26e6-4b77-b742-aaff9a449e1c XFS (sda1): Torn write (CRC failure) detected at log block 0x318e. Truncating head block CVSSv3.1 8.2 (HIGH)

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-08
2026-05-08 15:16Z
HIGH

CVE-2026-43362 — Linux: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix in-place

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43362

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix in-place encryption corruption in SMB2_write() SMB2_write() places write payload in iov[1..n] as part of rq_iov. smb3_init_transform_rq() pointer-shares rq_iov, so crypt_message() encrypts iov[1] in-place, replacing the original plaintext with ciphertext. On a replayable error, the retry sends the same iov[1] which now contains ciphertext instead of the original data, resulting in corruptio CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-08
2026-05-08 15:16Z
CRIT

CVE-2026-41588 — RELATE: Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key().

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41588

RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16. CVSSv3.1 9.0 (CRITICAL)

CWECWE 208VNDRelateTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-05-08
2026-05-08 15:16Z
CRIT

CVE-2026-41583 — Zfnd Zebra-script: Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41583

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 transactions which were enabled in the NU5 network upgrade. Zebra nodes could thus accept and eventually mine a block that would be considered invalid by zcashd nodes, creating a consensus split between Zebra and zcashd nodes. In a s CVSSv3.1 9.1 (CRITICAL)

CWECWE 573VNDZfndVNDZebraTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-08
2026-05-08 15:16Z
CRIT

CVE-2026-41574 — Nhost Nhost\/auth: Prior to version 0.49.1, Nhost automatically links an incoming OAuth identity to an existing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41574

Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incoming OAuth identity to an existing Nhost account when the email addresses match. This is only safe when the email has been verified by the OAuth provider. Nhost's controller trusts a profile.EmailVerified boolean that is set by each provider adapter. The vulnerability is that several provider adapters do not correctly populate this field they either silently dr CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDNhostTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-08
2026-05-08 15:16Z
HIGH

CVE-2026-41524 — Brave: Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41524

Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verbatim in the database and subsequently rendered with Laravel Blade's unescaped output directive {!! !!}. Any JavaScript or HTML injected by an editor-role user is permanently stored and executed in every visitor's browser upon page load. This issue has been patched via commit 6c56603. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDBraveTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-08
2026-05-08 15:16Z
CRIT

CVE-2026-37431 — Beauty: Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-37431

Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.php endpoint. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDBeautyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-08
2026-05-08 14:16Z
HIGH

CVE-2026-44339 — PraisonAI: Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonaiagents resolves unresolved tool names

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44339

PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonaiagents resolves unresolved tool names against module globals and __main__ after it fails to match the declared tool list and the registry. With the default agent configuration, _perm_allow is None, so undeclared non-dangerous tool names are not rejected by the permission gate. An attacker who can influence tool-call names can therefore invoke unintended appl CVSSv3.1 8.6 (HIGH)

CWECWE 470VNDPraisonaiTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-08
2026-05-08 14:16Z
CRIT

CVE-2026-44336 — Praison Praisonai: Dropping a Python .pth file into the user site-packages directory escalates this primitive to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44336

PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers four file-handling tools by default — praisonai.rules.create, praisonai.rules.show, praisonai.rules.delete, and praisonai.workflow.show. Each accepts a path or filename string from MCP tools/call arguments and joins it onto ~/.praison/rules/ (or, for workflow.show, accepts an absolute path) with no containment check. The JSON-RPC di CVSSv3.1 9.6 (CRITICAL)

CWECWE 94CWECWE 22CWECWE 829CWECWE 20VNDPraisonVNDPraisonaiTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-08
2026-05-08 14:16Z
CRIT

CVE-2026-44335 — Praison Praisonaiagents: Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44335

PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. This issue has been patched in version 1.6.32. CVSSv3.1 9.8 (CRITICAL)

CWECWE 918VNDPraisonVNDPraisonaiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-08
2026-05-08 14:16Z
HIGH

CVE-2026-44334 — PraisonAI: From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated tools.py auto-import behind PRAISONAI_ALLOW_LOCAL_TOOLS=true

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44334

PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated tools.py auto-import behind PRAISONAI_ALLOW_LOCAL_TOOLS=true in two files (tool_resolver.py, api/call.py). A third import sink in praisonai/templates/tool_override.py was missed and remains unguarded. It is reached by the recipe runner on every recipe execution and is remotely triggerable through POST /v1/recipes/run with a recipe value pointing at any local abso CVSSv3.1 8.4 (HIGH)

CWECWE 94VNDPraisonaiTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-08
2026-05-08 14:16Z
CRIT

CVE-2026-43341 — Linux: In the Linux kernel, the following vulnerability has been resolved: net/ipv6: ioam6: prevent schema

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43341

In the Linux kernel, the following vulnerability has been resolved: net/ipv6: ioam6: prevent schema length wraparound in trace fill ioam6_fill_trace_data() stores the schema contribution to the trace length in a u8. With bit 22 enabled and the largest schema payload, sclen becomes 1 + 1020 / 4, wraps from 256 to 0, and bypasses the remaining-space check. __ioam6_fill_trace_data() then positions the write cursor without reserving the schema area but still copies the 4-byte s CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score