HIGH7.5CVE-2026-44892Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
HIGH7.5CVE-2026-44890Netty has Unbounded Direct Memory Consumption in its RedisDecoder
HIGH7.5Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
HIGH8.1Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
MEDIUM5.4Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type
MEDIUM4.3MariaDB server is a community developed fork of MySQL server.
MEDIUM6.3MariaDB server is a community developed fork of MySQL server.
HIGH8.0MariaDB server is a community developed fork of MySQL server.
—MariaDB server is a community developed fork of MySQL server.
—MariaDB server is a community developed fork of MySQL server.
HIGH8.0MariaDB server is a community developed fork of MySQL server.
HIGH8.0MariaDB server is a community developed fork of MySQL server.
MEDIUM5.0MariaDB server is a community developed fork of MySQL server.
MEDIUM4.3Bugsink: DOS using large numbers of event tags
MEDIUM4.3Bugsink: Project scoping missing in sourcemap and debug-file lookup
LOW3.1Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
LOW3.1Bugsink: Issue event views can show an event from another project if its UUID is known
CRITICAL9.1NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)
HIGH8.3praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
—Vantage6: 2FA can be circumvented with hacked email access
—Vantage6: No limit on emails sent for password/MFA reset
MEDIUM6.5Authorization Bypass in SearchModelVersions in mlflow/mlflow
MEDIUM6.5Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path
HIGH7.3Apache Airflow: Arbitrary import in custom deadline-reference deserialization