HIGH7.8CVE-2026-54074@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
HIGH7.5flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key
HIGH8.8CedarJava has policy injection vulnerability
HIGH8.8CedarJava has type confusion vulnerability
HIGH8.3libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sf…
CRITICAL9.0HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allo…
LOW1.8A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation.
HIGH8.8An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in…
HIGH8.7HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tb…
HIGH7.1OpenClaw: Workspace-derived service PATH could influence trash command selection
HIGH7.1OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
HIGH8.1OpenClaw: Discord allowFrom could bind to mutable display names
HIGH7.1OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
HIGH7.1OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
HIGH8.1OpenClaw: Zalo allowFrom could bind to mutable display names
HIGH8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks
HIGH7.5undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
HIGH7.5http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
HIGH8.1piscina: Prototype Pollution Gadget → RCE via inherited options.filename
HIGH8.0Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator`
HIGH7.1OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
HIGH8.1OpenClaw: Shell inline-command parsing could miss an allowlist check
HIGH8.8OpenClaw: Pairing-scoped device session could restore revoked node token authority
HIGH8.1OpenClaw: Host environment sanitizer missed two Node.js control variables
HIGH7.5undici WebSocket client vulnerable to denial of service via fragment count bypass