{"success":true,"data":{"threats":[{"id":"03ac9e90-045a-4995-940b-17bcadc8a8bc","slug":"cve-2026-107289","externalId":"CVE-2026-107289","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107289 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.","description":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.56.0 until 1.107.6 and 2.44.0, applications that opt attacker-influenced URLs into local network access through FileUrl with force_download='allow-local' or web_fetch_tool with allow_local_urls=True can bypass the cloud-metadata blocklist by appending an IPv6 zone identifier to an IPv6 metadata address. IPv6Address equality and hashing include the zone identifier, so the blocklist comparison fails even though the network stack ignores the zone on a non-link-local destination and reaches the metadata service, potentially exposing cloud IAM credentials. The opt-in settings are disabled by default, and the issue requires an IPv6-enabled environment. This issue is fixed in versions 1.107.6 and 2.44.0.","cveId":"CVE-2026-107289","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","severity":"medium","vendor":"PyPI","product":"pydantic-ai","affectedVersions":["pkg:pypi/pydantic-ai >= 1.56.0, < 1.107.6","pkg:pypi/pydantic-ai >= 2.0.0b1, < 2.44.0","pkg:pypi/pydantic-ai-slim >= 1.56.0, < 1.107.6","pkg:pypi/pydantic-ai-slim >= 2.0.0b1, < 2.44.0"],"cwes":["CWE-918","CWE-1289"],"tags":["nvd","status:received","osv","osv:ghsa-vmxc-h2x2-jmf3","ecosystem:pypi","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/02157e1b87bd45d3f2e111ce07afdf89f9fb0e5b","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/4da70591460f51a8c4f128eaeef70a33340dbd55","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8401","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8402","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-vmxc-h2x2-jmf3","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-vmxc-h2x2-jmf3","type":"advisory","title":"OSV GHSA-vmxc-h2x2-jmf3"},{"url":"https://github.com/pydantic/pydantic-ai","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:17:04.337Z","addedAt":"2026-10-08T16:39:36.025Z","updatedAt":"2026-10-08T21:05:50.771Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107289","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107289","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-VMXC-H2X2-JMF3"}]},{"id":"07e8b501-d5b4-48c7-a532-0ad4fd786942","slug":"cve-2026-107288","externalId":"CVE-2026-107288","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107288 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.","description":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback compare blocked_domains entries with a URL hostname before both values are normalized to the form used by getaddrinfo. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string, causing the application to fetch that host with its own privileges. allowed_domains fails closed for unmatched spellings, and private-IP and cloud-metadata protections remain effective. This issue is fixed in versions 1.107.6 and 2.44.0.","cveId":"CVE-2026-107288","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918","CWE-1289"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/490335f8e2322e143a79337ddca9410e0176c812","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/a9dab92099d0ef9d5d4aa34ccac8a6f1b0e51284","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/c1f212a084cbfa0012f2044cdb4731d214b3b983","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8407","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8409","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8421","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-22h6-qm39-v87j","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:17:04.147Z","addedAt":"2026-10-08T16:39:36.017Z","updatedAt":"2026-10-08T21:05:50.743Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107288","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107288","note":"authoritative record"}]},{"id":"776b65af-f0f6-4315-a236-2da5237ca9b8","slug":"cve-2026-102478","externalId":"CVE-2026-102478","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102478 — In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse …","description":"In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.","cveId":"CVE-2026-102478","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1289"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://advisories.octopus.com/post/2026/sa2026-11","type":"advisory","title":"security@octopus.com"}],"epssScore":0.00295,"epssPercentile":0.20346,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T02:16:56.320Z","addedAt":"2026-10-07T02:39:29.166Z","updatedAt":"2026-10-07T20:39:39.972Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102478","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102478","note":"authoritative record"}]},{"id":"4881e9bc-9fc3-4670-bbc2-4e49ce3fb0d5","slug":"cve-2026-106445","externalId":"CVE-2026-106445","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106445 — Handlebars provides the power necessary to let users build semantic templates.","description":"Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. This permits attacker-controlled JavaScript to execute with the server application's privileges. This issue is fixed in version 4.7.10.","cveId":"CVE-2026-106445","cvssScore":9.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"npm","product":"handlebars","affectedVersions":["pkg:npm/handlebars >= 4.0.0, < 4.7.10"],"cwes":["CWE-184","CWE-1289"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-p8wg-vrv2-v86f","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/handlebars-lang/handlebars.js/commit/ceec388abe1d1aac8f6369860d5f390fa71ef4fa","type":"other","title":"OSV web"},{"url":"https://github.com/handlebars-lang/handlebars.js/pull/2185","type":"other","title":"OSV web"},{"url":"https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.10","type":"other","title":"OSV web"},{"url":"https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-p8wg-vrv2-v86f","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-p8wg-vrv2-v86f","type":"advisory","title":"OSV GHSA-p8wg-vrv2-v86f"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106445","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/handlebars-lang/handlebars.js","type":"vendor","title":"OSV package"}],"epssScore":0.00411,"epssPercentile":0.33314,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:26.293Z","addedAt":"2026-10-06T20:39:33.050Z","updatedAt":"2026-10-08T18:42:41.951Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106445","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106445","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-P8WG-VRV2-V86F"}]},{"id":"3f4f091c-ab6e-45f2-bd8a-4bbe73946845","slug":"cve-2026-105048","externalId":"CVE-2026-105048","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105048 — The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).","description":"The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).","cveId":"CVE-2026-105048","cvssScore":4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1289"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bishopfox.com/blog/zilliz-attu-2-6-5","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/zilliztech/attu/issues/1028","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00191,"epssPercentile":0.08005,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T23:16:57.787Z","addedAt":"2026-10-02T23:50:39.728Z","updatedAt":"2026-10-06T17:50:41.759Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105048","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105048","note":"authoritative record"}]},{"id":"c01ad295-3938-4973-a48e-f57156cfeaa1","slug":"cve-2026-100255","externalId":"CVE-2026-100255","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100255 — In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset","description":"In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset","cveId":"CVE-2026-100255","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"jetbrains","product":"teamcity","affectedVersions":["< 2025.11.8",">= 2026.1, < 2026.1.4"],"cwes":["CWE-1289"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.jetbrains.com/privacy-security/issues-fixed/","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.0035,"epssPercentile":0.26553,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:16:56.100Z","addedAt":"2026-09-30T17:50:47.635Z","updatedAt":"2026-10-02T21:50:39.941Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100255","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100255","note":"authoritative record"}]},{"id":"2cc4dfce-a339-40a7-ba82-713eeaf15419","slug":"cve-2026-97196","externalId":"CVE-2026-97196","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97196 — Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass.","description":"Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass.\n\nThis issue affects GiveWP: from n/a through 4.16.9.","cveId":"CVE-2026-97196","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1289"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-9-broken-authentication-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00296,"epssPercentile":0.20455,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T07:16:31.320Z","addedAt":"2026-09-30T07:50:39.533Z","updatedAt":"2026-09-30T15:50:42.532Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97196","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97196","note":"authoritative record"}]},{"id":"4532b42b-e5b3-4198-b8cd-627fa1bced1f","slug":"cve-2026-101015","externalId":"CVE-2026-101015","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-101015 — A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2.","description":"A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cveId":"CVE-2026-101015","cvssScore":5.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-20","CWE-1289"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://vuldb.com/cve/CVE-2026-101015","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/917216","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/410885","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/410885/cti","type":"advisory","title":"cna@vuldb.com"},{"url":"https://weitongli.com/share/opendmarc-unicode-dot-bypass.html","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00293,"epssPercentile":0.20103,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T09:17:05.180Z","addedAt":"2026-09-28T09:50:38.745Z","updatedAt":"2026-10-01T15:50:39.983Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101015","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-101015","note":"authoritative record"}]},{"id":"dd6a7223-1576-4e66-aad4-b7409f11f9e2","slug":"cve-2026-100837","externalId":"CVE-2026-100837","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100837 — Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller.","description":"Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses strings.HasSuffix(hostname, fqdn) without requiring a DNS label boundary, so a registry entry such as [registries.\"ghcr.io.\"] is also applied to any host whose name merely ends in that byte sequence, including attacker-registered domains such as evilghcr.io. When an image or layer is pulled from such a sibling domain, the imagepuller sends the configured Authorization header (basic auth, registry token, or identity token), trusts the configured custom CA bundle, follows the configured mirror, and honours insecure-skip-verify (disabling TLS verification) for that host. Image integrity is not affected, as image bytes remain pinned by digest in the policy and are validated after the pull. Configurations that use a leading dot (e.g., [registries.\".example.registry\"]) are unaffected.","cveId":"CVE-2026-100837","cvssScore":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"Go","product":"github.com/edgelesssys/contrast","affectedVersions":["pkg:golang/github.com/edgelesssys/contrast < 1.21.0"],"cwes":["CWE-1289"],"tags":["nvd","status:received","osv","osv:ghsa-6c87-g9pw-78fx","ecosystem:go","osv:go-2026-5865","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/edgelesssys/contrast/commit/10826b1d82613025767fb094e8aa51a7dcfbd2a1"],"references":[{"url":"https://github.com/edgelesssys/contrast/security/advisories/GHSA-6c87-g9pw-78fx","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/edgeless-systems-contrast-through-1.20.0-credential-leak-via-registry-suffix-matching","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://osv.dev/vulnerability/GHSA-6c87-g9pw-78fx","type":"advisory","title":"OSV GHSA-6c87-g9pw-78fx"},{"url":"https://github.com/edgelesssys/contrast/commit/10826b1d82613025767fb094e8aa51a7dcfbd2a1","type":"patch","title":"OSV fix"},{"url":"https://github.com/edgelesssys/contrast","type":"vendor","title":"OSV package"},{"url":"https://github.com/edgelesssys/contrast/releases/tag/v1.21.0","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GO-2026-5865","type":"advisory","title":"OSV GO-2026-5865"}],"epssScore":0.00213,"epssPercentile":0.10604,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-27T02:17:21.937Z","addedAt":"2026-09-27T03:50:37.842Z","updatedAt":"2026-09-30T17:50:45.331Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100837","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100837","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-6C87-G9PW-78FX"}]},{"id":"1d2d0e22-0151-4190-a454-0bedcccb52c1","slug":"cve-2026-86831","externalId":"CVE-2026-86831","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86831 — Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authen…","description":"Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces via crafted pod and namespace names that produce pod identifier collisions.\n\n\n\nTo remediate this issue, users should upgrade to Amazon EKS Network Policy Agent 1.4.0 or later and Amazon VPC CNI Managed Add-on v1.22.4 or later (which includes Network Policy Agent v1.4.0).","cveId":"CVE-2026-86831","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1289"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/aws/amazon-vpc-cni-k8s/releases/tag/v1.22.4","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/amazon-vpc-cni-k8s/security/advisories/GHSA-gjc7-c7mx-x8f3","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/aws-network-policy-agent/releases/tag/v1.4.0","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/aws-network-policy-agent/security/advisories/GHSA-7xv7-8r3j-3j25","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://staging.prod.website.marketing.aws.dev/security/security-bulletins/2026-113-aws/","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"epssScore":0.00643,"epssPercentile":0.49255,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T20:17:36.980Z","addedAt":"2026-09-16T21:50:38.871Z","updatedAt":"2026-09-17T17:50:43.878Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86831","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86831","note":"authoritative record"}]},{"id":"4865e9cb-6bd3-4909-bf15-e0a10da5ec24","slug":"cve-2026-88255","externalId":"CVE-2026-88255","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88255 — Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Tempo duplicate-submission ga…","description":"Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Tempo duplicate-submission gate twice with one signed transaction.\n\nMPP.Methods.Tempo reserves the pre-broadcast dedup slot on the caller-supplied hex in reserve_hash_atomic/2, keyed through store_key/1 on tx.raw rather than on a canonical form of the transaction. The deserializer stores the caller's hex verbatim and accepts both recovery-id encodings, so one signed transaction submitted once with v=27 and once with v=0 yields two distinct reserve keys, and both pass the reserve and reach the broadcast path. The plug-level credential replay store is deliberately carved out for tempo in lib/mpp/replay.ex, leaving this reserve as the only gate, and the post-broadcast mark writes the canonical hash key that the raw-keyed reserve never reads.\n\nWhat the duplicate submission yields depends on the node: a nonce-reuse rejection fails closed, while a node that answers with the canonical hash for an already-known transaction returns a second valid Payment-Receipt for a single on-chain payment.\n\nThis issue affects mpp: from 0.2.0 before 0.16.2.","cveId":"CVE-2026-88255","cvssScore":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1289"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cna.erlef.org/cves/CVE-2026-88255.html","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ZenHive/mpp/commit/e12bd4a1cea2e97c2a01fc059c48e5594a7b4a43","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ZenHive/mpp/commit/f8904666061fbab695874856d8fcd02c471dfe1b","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ZenHive/mpp/security/advisories/GHSA-8x7x-5j8g-8hcx","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-88255","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"}],"epssScore":0.00524,"epssPercentile":0.42611,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T09:17:07.333Z","addedAt":"2026-09-16T09:50:35.895Z","updatedAt":"2026-09-16T21:50:38.415Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88255","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88255","note":"authoritative record"}]},{"id":"a9393734-6bba-4690-b9e9-b5f4dd490330","slug":"cve-2026-89049","externalId":"CVE-2026-89049","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-89049 — A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functio…","description":"A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address.\n\n\n\nTo remediate this issue, users should upgrade to version 3.3.4851.0 or later.","cveId":"CVE-2026-89049","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-918","CWE-1289"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-107-aws/","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/amazon-ssm-agent/releases/tag/3.3.4851.0","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/amazon-ssm-agent/security/advisories/GHSA-w9jw-h72g-6hxc","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"epssScore":0.00662,"epssPercentile":0.50115,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-10T19:17:42.373Z","addedAt":"2026-09-10T19:50:35.441Z","updatedAt":"2026-09-10T19:50:35.441Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89049","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-89049","note":"authoritative record"}]},{"id":"82afbee2-f43d-4d8c-a6aa-6e6d010c6add","slug":"cve-2026-76977","externalId":"CVE-2026-76977","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76977 — SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist.","description":"SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's page and interacts with it, the attacker could trick the victim into performing unintended actions, resulting in a low impact on integrity. There is no impact on confidentiality and availability.","cveId":"CVE-2026-76977","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1289"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://me.sap.com/notes/3783189","type":"advisory","title":"cna@sap.com"},{"url":"https://url.sap/sapsecuritypatchday","type":"advisory","title":"cna@sap.com"}],"epssScore":0.00372,"epssPercentile":0.29019,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T01:17:55.653Z","addedAt":"2026-09-08T01:50:33.158Z","updatedAt":"2026-09-08T19:50:37.653Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76977","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76977","note":"authoritative record"}]},{"id":"81617618-23b5-41b9-be28-89922bfaf54d","slug":"cve-2026-74994","externalId":"CVE-2026-74994","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-74994 — The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration b…","description":"The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.","cveId":"CVE-2026-74994","cvssScore":6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863","CWE-1289"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cna.erlef.org/cves/CVE-2026-74994.html","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/erlang/otp/commit/6101cb74ff2870718c622ba7af0c100f7f2524e3","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/erlang/otp/commit/6982e381137ede21a4e1faf5fa2dd82321691176","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/erlang/otp/commit/c5ccec8ed25c70ec6557fd81277e4b2f52285c19","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/erlang/otp/security/advisories/GHSA-c3cq-q8x6-547g","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-74994","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"}],"epssScore":0.00633,"epssPercentile":0.4874,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-01T15:17:25.927Z","addedAt":"2026-09-01T15:50:35.148Z","updatedAt":"2026-09-08T03:50:32.764Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74994","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-74994","note":"authoritative record"}]},{"id":"c2ea41c2-e7e3-4e0f-853d-7c5c77f01191","slug":"cve-2026-19953","externalId":"CVE-2026-19953","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19953 — URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep.","description":"URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep.\n\nnameprep lowercases each host label but performs no Unicode normalization. IDNA requires a label to be normalized to Form C before it is encoded (RFC 5891), so a label that is not already in NFC is encoded to a different A-label than its normalized form. A label built from the precomposed Devanagari sequence U+0958 U+093E encodes to xn--72b5c without normalization but to xn--11b2fg after NFC normalization, and xn--72b5c does not round-trip back to the original label.\n\nAny caller that reads host() from a URI built from untrusted input and uses it for a security decision (an allow or deny list, an SSRF filter, deduplication, a cache key) sees the non-standard label, while a client that fetches the same URL resolves the NFC form, so the check and the fetch can disagree about the host.","cveId":"CVE-2026-19953","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1289"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/libwww-perl/URI/commit/956619a9e94f86d8d2c529b4e06a3674c54a73e7.patch","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://github.com/libwww-perl/URI/pull/191","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/OALDERS/URI-5.36/changes","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://www.rfc-editor.org/rfc/rfc5891#section-5.2","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/31/14","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00229,"epssPercentile":0.1262,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-31T18:17:14.320Z","addedAt":"2026-08-31T19:50:35.165Z","updatedAt":"2026-09-03T17:50:34.354Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19953","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19953","note":"authoritative record"}]},{"id":"598412ca-4804-45da-8b2d-1e1b4fca7c42","slug":"cve-2026-60074","externalId":"CVE-2026-60074","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-60074 — Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check.","description":"Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check.\n\nThe parse regexes capture year, month and day with the `\\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\\p{Nd}` and not just `[0-9]`. Date::Manip::Base::check then validates the captured fields with numeric comparisons alone (`$y<1 || $y>9999`, `$m<1 || $m>12`, `$d<1 || $d>$days`), and _parse_check stores the numified fields (`$y+0`). Perl truncates a string at the first character that is not an ASCII digit, so a field whose leading characters are ASCII digits numifies to an in-range prefix and satisfies every test: a year field of three ASCII digits followed by U+0664 ARABIC-INDIC DIGIT FOUR numifies to 202, giving the year 0202, and one non-ASCII digit in the month or day field shifts those fields the same way. The hour, minute and second fields match explicit ASCII character classes (`0?[0-9]`, `[0-5][0-9]`) and do not shift, though a non-ASCII digit in a fractional hour or minute field truncates the fraction.\n\nAny caller that passes an untrusted character string to ParseDate() or Date::Manip::Date->parse() can get back a date that differs from the string it parsed, with no parse error. Where the parsed date gates logic such as an expiry check or a retention window, the shift goes unnoticed.","cveId":"CVE-2026-60074","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1289"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Base.pm#L602-614","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Date.pm#L1536-1539","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60074-r1.patch","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/30/19","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/SBECK-github/Date-Manip/pull/54","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epssScore":0.0063,"epssPercentile":0.48565,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-30T14:17:02.587Z","addedAt":"2026-07-30T14:24:02.276Z","updatedAt":"2026-09-02T13:50:36.762Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60074","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-60074","note":"authoritative record"}]},{"id":"c5bcfb75-5617-455e-9c6b-49d97adc91ed","slug":"cve-2026-42462","externalId":"CVE-2026-42462","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-42462 — Fedify is a TypeScript library for building federated server apps powered by ActivityPub.","description":"Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to restructure a JSON-LD document that would change how Fedify interprets it without changing its Linked Data Signature, allowing them to alter a third-party signed activity they have received. Versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3 fix the issue.","cveId":"CVE-2026-42462","cvssScore":7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-180","CWE-347","CWE-436","CWE-1289"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/fedify-dev/fedify/releases/tag/2.2.3","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/fedify-dev/fedify/security/advisories/GHSA-9rfg-v8g9-9367","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00249,"epssPercentile":0.14814,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-06-10T22:16:57.387Z","addedAt":"2026-07-28T20:12:22.689Z","updatedAt":"2026-07-28T20:12:22.689Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42462","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-42462","note":"authoritative record"}]},{"id":"2c338cdb-f11f-40fc-a453-707efb450f24","slug":"cve-2026-47674","externalId":"GHSA-xrhx-7g5j-rcj5","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Hono: IP Restriction bypasses static deny rules for non-canonical IPv6","description":"### Summary\n\nThe `ip-restriction` middleware (`hono/ip-restriction`) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 representations of an address already listed in a static rule — such as compressed forms, explicit-zero forms, or hex-notation IPv4-mapped addresses — do not match the normalized rule entry, causing the rule to be silently skipped.\n\n### Details\n\nWhen the rule matcher is built, each configured IP rule is normalized to a canonical string form. Incoming IP addresses received at request time are then compared against those canonical strings without applying the same normalization. Because IPv6 permits multiple syntactically different representations of the same numeric address, a non-canonical form of a denied address fails the string lookup and proceeds to the CIDR check, which also finds no match for rules registered as static (no prefix length). The request is then allowed.\n\nAffected non-canonical forms include:\n\n- Compressed versus expanded notation (`2001:db8::1` vs `2001:db8:0:0:0:0:0:1`)\n- Hex-notation IPv4-mapped addresses (`::ffff:7f00:1` vs `::ffff:127.0.0.1`)\n- Zone identifier suffixes (e.g., `fe80::1%eth0`)\n\nAdditionally, invalid IP address strings provided as the remote address are not rejected and may result in unexpected allow or deny behavior.\n\nThis issue arises when applications use `ipRestriction()` with static (non-CIDR) rules and the IP address source can supply addresses in non-canonical IPv6 form.\n\n### Impact\n\nA request from an IP address covered by a static deny rule may bypass the restriction if the address is presented in a non-canonical IPv6 form.\n\nThis may lead to:\n\n- Unauthorized access to endpoints intended to be restricted to specific IP addresses\n- Bypass of IP-based access controls in environments where the runtime or an upstream proxy provides source addresses in a form that differs from the canonical form used in the rule configuration\n\nThis issue affects applications using `hono/ip-restriction` with static deny rules for IPv4 or IPv6 addresses, particularly when the source address is derived from proxy headers or custom `getIP` implementations that may return non-canonical forms.","cveId":"CVE-2026-47674","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":"npm","product":"hono","affectedVersions":["pkg:npm/hono < 4.12.21"],"cwes":["CWE-1289","CWE-185"],"tags":["osv","osv:ghsa-xrhx-7g5j-rcj5","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-xrhx-7g5j-rcj5","type":"advisory","title":"OSV GHSA-xrhx-7g5j-rcj5"},{"url":"https://github.com/honojs/hono/security/advisories/GHSA-xrhx-7g5j-rcj5","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47674","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/honojs/hono/commit/c831020fb1fa2e929d222f6c84e1abfe013e512b","type":"other","title":"OSV web"},{"url":"https://github.com/honojs/hono","type":"vendor","title":"OSV package"},{"url":"https://github.com/honojs/hono/releases/tag/v4.12.21","type":"other","title":"OSV web"}],"epssScore":0.0031,"epssPercentile":0.21899,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-06-04T18:00:22.000Z","addedAt":"2026-09-10T07:55:08.552Z","updatedAt":"2026-09-10T07:55:08.552Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47674","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-47674","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-xrhx-7g5j-rcj5"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-xrhx-7g5j-rcj5"}]},{"id":"39cc3732-3637-4683-99b6-110ec39b29f8","slug":"cve-2026-49942","externalId":"CVE-2026-49942","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-49942 — Net::CIDR::Set versions through 0.20 for Perl did not validate network masks.","description":"Net::CIDR::Set versions through 0.20 for Perl did not validate network masks.\n\nThe mask portion of a network mask could contain Unicode digits such as the Arabic-Indic One (U+0661), or non-digits, which were ignored.   This could allow network masks to accept larger networks.\n\nLeading zeros were also accepted, but treated as decimal instead of octal.  This could lead to confusion about what networks are acceptable.","cveId":"CVE-2026-49942","cvssScore":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","severity":"high","vendor":"rrwo","product":"net\\","affectedVersions":["< 0.21"],"cwes":["CWE-1289"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://metacpan.org/release/RRWO/Net-CIDR-Set-0.21/changes","type":"advisory","title":"Release Notes"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-40911","type":"advisory","title":"Third Party Advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45191","type":"advisory","title":"Third Party Advisory"}],"epssScore":0.00488,"epssPercentile":0.40103,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-06-04T17:16:33.283Z","addedAt":"2026-07-28T20:12:15.761Z","updatedAt":"2026-07-28T20:12:15.761Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49942","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-49942","note":"authoritative record"}]},{"id":"f9717da7-6835-44e8-926e-2abc1b8a3243","slug":"cve-2026-49940","externalId":"CVE-2026-49940","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-49940 — Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks.","description":"Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks.\n\nUnicode digits such as the Arabic-Indic One (U+0661) were accepted but not properly parsed as numbers.  This could allow network masks to accept larger networks.","cveId":"CVE-2026-49940","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":"rrwo","product":"net\\","affectedVersions":["< 0.21"],"cwes":["CWE-1289"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://metacpan.org/release/RRWO/Net-CIDR-Set-0.21/changes","type":"advisory","title":"Release Notes"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-40911","type":"advisory","title":"Third Party Advisory"}],"epssScore":0.00295,"epssPercentile":0.2034,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-06-04T17:16:33.053Z","addedAt":"2026-07-28T20:12:15.755Z","updatedAt":"2026-07-28T20:12:15.755Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49940","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-49940","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":28,"totalPages":2,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T00:26:01.292Z","durationMs":42,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-1289"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}