THREAT OPS › Threat News
Threat Intelligence News
11844 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- OpenSSL Security Advisoryoss_sec · 2026-08-13
- [NVD] CVE-2026-8715 (CRITICAL 9.6) — Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and tranvd · 2026-08-13
- [GHSA] GHSA-p28v-f755-9qrg (high) — Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoSgithub_advisories · 2026-08-13
- [coinbasecartel] Hitachi High-Tech posted to leak siteransomware_live · 2026-08-13
- [OSSN-0107] Ironic-Python-Agent: Container HardwareManager Security Model Misimplementedoss_sec · 2026-08-13
- [GHSA] GHSA-m42h-3232-vpv3 (high) — nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequencesgithub_advisories · 2026-08-13
- Go 1.26.6 and Go 1.25.13 are released with 10 security fixesoss_sec · 2026-08-13
- [OSSA-2026-035] OpenStack Octavia: Unauthorized QoS policy deletion lock (CVE pending)oss_sec · 2026-08-13
- CVE-2026-13051: Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext templateoss_sec · 2026-08-13
- CVE-2026-13048: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filenameoss_sec · 2026-08-13
- CVE-2026-66256: Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)oss_sec · 2026-08-13
- CVE-2022-4993: HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation templateoss_sec · 2026-08-13
- [NVD] CVE-2026-73656 (CRITICAL 9.9) — Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeploymentBackgroundWonvd · 2026-08-13
- [NVD] CVE-2026-73655 (HIGH 7.4) — Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in apps/webapp/app/models/user.server.ts withnvd · 2026-08-13
- [NVD] CVE-2026-73654 (HIGH 8.5) — Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the PUT /api/v1/runs/:runId/metadata endpoint passes attacker-controlled operation.key values to new JSONHeroPath(operation.key).set(newMetadata, value) in packagesnvd · 2026-08-13
- [NVD] CVE-2026-72676 (MEDIUM 6.5) — Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Kibana accepted an identifier for an output configuration without restricting it to safe characters. Thnvd · 2026-08-13
- [NVD] CVE-2026-72672 (HIGH 7.7) — The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verinvd · 2026-08-13
- [NVD] CVE-2026-72671 (MEDIUM 4.3) — A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anonvd · 2026-08-13
- [NVD] CVE-2026-72670 (HIGH 7.7) — A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials anvd · 2026-08-13
- [NVD] CVE-2026-72669 (HIGH 7.6) — The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover thnvd · 2026-08-13
- [NVD] CVE-2026-72657 (MEDIUM 6.5) — Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-supplied value that was persisted without beinnvd · 2026-08-13
- [NVD] CVE-2026-72656 (MEDIUM 6.5) — Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocanvd · 2026-08-13
- [NVD] CVE-2026-72655 (MEDIUM 4.3) — Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privilegesnvd · 2026-08-13
- [NVD] CVE-2026-72648 (MEDIUM 6.5) — Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive Data (CAPEC-37). When ECK reconciles a Fleet Server resource that authenticates to Elasticsearchnvd · 2026-08-13
- [NVD] CVE-2026-59714 (HIGH 7.1) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion requesnvd · 2026-08-13
- [NVD] CVE-2026-45774 — compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves `trestle://` URIs and relative file paths by joining them with `trestle_root` and calling `.resolve()`,nvd · 2026-08-13
- [NVD] CVE-2026-45725 — compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without nvd · 2026-08-13
- CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)oss_sec · 2026-08-13
- CVE-2026-19487: Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclassoss_sec · 2026-08-13
- [NVD] CVE-2026-73652 — vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorithm while it is pending or under review. The nvd · 2026-08-13
- [NVD] CVE-2026-73651 (MEDIUM 5.7) — TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases. Prior to versions 0.3.31 and 1.1.0, typeorm migration:generate embeds database schema metadata into JavaScript or TypeScript template nvd · 2026-08-13
- [NVD] CVE-2026-73650 (HIGH 8.2) — SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimnvd · 2026-08-13
- GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCEthehackernews · 2026-08-13
- [GHSA] GHSA-87x5-vmc3-756j (medium) — vLLM: Completion prompt lists fan out into unbounded engine requestsgithub_advisories · 2026-08-13
- [NVD] CVE-2026-73649 (CRITICAL 9.8) — Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/cnvd · 2026-08-13
- [NVD] CVE-2026-73648 — rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href anvd · 2026-08-13
- [NVD] CVE-2026-73645 — OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM. Prior to 0.3.1, the ERC7984 contract tracked confidential total supply with an euint64 value, and an overflowing internal _mint operation could fail silently. The wrap annvd · 2026-08-13
- [NVD] CVE-2026-73644 (CRITICAL 9.6) — OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxynvd · 2026-08-13
- [NVD] CVE-2026-73643 (HIGH 7.5) — js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls load() or loadAll() on untrusted input. In src/parser/parser.ts, readFlowCollection uses restoreState and calls parseNode a senvd · 2026-08-13
- [NVD] CVE-2026-73569 — fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through adnvd · 2026-08-13
- [NVD] CVE-2026-73568 (HIGH 7.5) — py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly() before validating it against MAX_WINDOW_nvd · 2026-08-13
- [NVD] CVE-2026-73567 (CRITICAL 9.1) — sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/utils.js, supplied by jsbn@1.1.0, which nvd · 2026-08-13
- [NVD] CVE-2026-73566 (HIGH 7.5) — node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty membenvd · 2026-08-13
- [NVD] CVE-2026-73564 — frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF makes the uint32 addition wrap to 3, defeats nvd · 2026-08-13
- [NVD] CVE-2026-73563 (MEDIUM 4.7) — Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch glob matching for auth.experimentalDynamicClnvd · 2026-08-13
- [NVD] CVE-2026-73562 (MEDIUM 6.5) — Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted pathnvd · 2026-08-13
- ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Storiesthehackernews · 2026-08-13
- Curiouser and Curiousertalos · 2026-08-13
- [rhysida] SIA Medical Centre posted to leak siteransomware_live · 2026-08-13
- AI 'watermark removers' flood the web. Almost none can prove they work.bleepingcomputer · 2026-08-13
- How to Improve Cloud Security Posture With CSPM: Visualizing the Attack Pathorca_security · 2026-08-13
- [NVD] CVE-2026-73266 (HIGH 7.1) — A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. nvd · 2026-08-13
- [NVD] CVE-2026-55402 (MEDIUM 5.9) — CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service.nvd · 2026-08-13
- Why API Discovery Is Critical for Modern AppSec Programsqualys · 2026-08-13
- [NVD] CVE-2026-73576 (MEDIUM 6.3) — In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtainnvd · 2026-08-13
- [NVD] CVE-2026-73575 (LOW 3.1) — In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by nvd · 2026-08-13
- [NVD] CVE-2026-73574 (LOW 3.1) — In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially anvd · 2026-08-13
- [NVD] CVE-2026-73573 (LOW 3.1) — In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path trnvd · 2026-08-13
- [NVD] CVE-2026-73572 (MEDIUM 6.1) — In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicionvd · 2026-08-13
- [NVD] CVE-2026-73571 (LOW 3.1) — An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emanvd · 2026-08-13
- [NVD] CVE-2026-73570 (HIGH 8.9) — A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticatednvd · 2026-08-13
- [NVD] CVE-2026-55401 (MEDIUM 5.3) — CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashingnvd · 2026-08-13
- [NVD] CVE-2026-55400 (MEDIUM 6.5) — CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a persistent denial of service.nvd · 2026-08-13
- Project Glasswing and the Coming Inversion of Vulnerability Managementzscaler_threatlabz · 2026-08-13
- Return of the Cookie Monsterspecterops · 2026-08-13
- Attack of The Extensionsspecterops · 2026-08-13
- [NVD] CVE-2026-73509 (HIGH 7.6) — OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with checkRelativnvd · 2026-08-13
- [NVD] CVE-2026-49857 (HIGH 7.4) — auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `assertSafeUrl()` (`src/security.ts`) to block requests to private and loopback addresses. However, the `isPrivateV6()` function fails tnvd · 2026-08-13
- [NVD] CVE-2026-49856 (MEDIUM 4.3) — @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authorization policy that blocks private, loopback, link-local, and reserved targets unless an explicit authorizationvd · 2026-08-13
- [NVD] CVE-2026-49820 (MEDIUM 4.7) — Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML, session transfer, OAuth connectors, and trust-center magic linksnvd · 2026-08-13
- WebPros security advisory (AV26-815)cccs_ca · 2026-08-13
- Why Validation Changes Everything. But Isn’t Enough.horizon3 · 2026-08-13
- Closing the Data Security Gap: How AHEAD Built a Full-Stack Zscaler Practicezscaler_threatlabz · 2026-08-13
- New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructurethehackernews · 2026-08-13
- Shadow AI: Risks, Detection, and Security Strategiesorca_security · 2026-08-13
- [dragonforce] GB Group S.A posted to leak siteransomware_live · 2026-08-13
- [GHSA] GHSA-rm43-82j9-r4mj (high) — atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file readgithub_advisories · 2026-08-13
- [NVD] CVE-2026-48702 (HIGH 7.5) — Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the nvd · 2026-08-13
- [GHSA] GHSA-h7p7-w5gc-xj3w (medium) — Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentialsgithub_advisories · 2026-08-13
- [GHSA] GHSA-48p8-g2fx-3wwm (high) — Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)github_advisories · 2026-08-13
- [GHSA] GHSA-5pq8-3ffp-7w5m (medium) — hashi-vault-js: Vault token and secret values exposed in thrown errorsgithub_advisories · 2026-08-13
- [GHSA] GHSA-vqfp-p66c-xrp9 (medium) — ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author tokengithub_advisories · 2026-08-13
- [GHSA] GHSA-2jwf-f4xq-f24h (medium) — ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwritegithub_advisories · 2026-08-13
- GitLab security advisory (AV26-814)cccs_ca · 2026-08-13
- [GHSA] GHSA-fjgc-3mj7-8rg8 (medium) — ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Headergithub_advisories · 2026-08-13
- [GHSA] GHSA-2mhj-fhvg-v428 (high) — Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table namegithub_advisories · 2026-08-13
- AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOSthehackernews · 2026-08-13
- AMD security advisory (AV26-813)cccs_ca · 2026-08-13
- Navigating AI-Driven Cyber Threats: Insights from Flashpoint’s 2026 GTIR Midyear Editionflashpoint · 2026-08-13
- [qilin] D & J Beverage Service posted to leak siteransomware_live · 2026-08-13
- [akira] CF Supply posted to leak siteransomware_live · 2026-08-13
- [NVD] CVE-2026-6471 (HIGH 7.2) — Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. nvd · 2026-08-13
- [NVD] CVE-2026-6470 (MEDIUM 4.3) — Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type fnvd · 2026-08-13
- [NVD] CVE-2026-6469 (LOW 3.8) — Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies thnvd · 2026-08-13
- [NVD] CVE-2026-6464 (HIGH 8.1) — Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql pronvd · 2026-08-13
- [NVD] CVE-2026-49827 (CRITICAL 9.8) — WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registranvd · 2026-08-13
- [NVD] CVE-2026-19385 (HIGH 8.8) — Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affectednvd · 2026-08-13
- [NVD] CVE-2026-18408 (HIGH 8.8) — Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fnvd · 2026-08-13
- [NVD] CVE-2026-18024 (MEDIUM 4.3) — Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before Postgrenvd · 2026-08-13
- [NVD] CVE-2026-16241 (LOW 3.8) — Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or nvd · 2026-08-13