{"success":true,"data":{"threats":[{"id":"bf71a3ad-9b6b-408e-9069-844632cf016d","slug":"cve-2026-107737","externalId":"CVE-2026-107737","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107737 — SumatraPDF is a multi-format reader for Windows.","description":"SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, and in pre-release 3.7.0.20369 when WebView2 is absent or cannot initialize, ParseProtoUrl() accepts the signed host component of an its:// URL and FindHtmlWindowById() uses it directly as an index into gHtmlWindows. Opening a crafted CHM through the IE fallback backend with a negative or otherwise out-of-range window identifier can cause an out-of-bounds pointer read followed by an invalid object callback dereference and process termination. No fixed version is available as of this review.","cveId":"CVE-2026-107737","cvssScore":5.7,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-129"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/sumatrapdfreader/sumatrapdf/commit/596c7e26e983549a77a3a38cae1147ab73792929","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-8p34-f32f-7rmq","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T23:16:59.760Z","addedAt":"2026-10-09T01:06:18.806Z","updatedAt":"2026-10-09T01:06:18.806Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107737","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107737","note":"authoritative record"}]},{"id":"40eb8202-cecf-4fbe-9e4f-b8a81b91aa68","slug":"cve-2026-107325","externalId":"CVE-2026-107325","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107325 — Improper validation of a BSON array length in the MongoDB Go Driver can cause an out-of-bounds index and runtime panic when an application calls bs…","description":"Improper validation of a BSON array length in the MongoDB Go Driver can cause an out-of-bounds index and runtime panic when an application calls bson.RawArray.Validate or bsoncore.Array.Validate on a malformed four-byte array. An unauthenticated actor who can supply raw BSON array data to an affected application may terminate an unprotected application process, causing a denial of service. No confidentiality or integrity impact has been identified.","cveId":"CVE-2026-107325","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-129"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://jira.mongodb.org/browse/GODRIVER-4136","type":"advisory","title":"cna@mongodb.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:00.173Z","addedAt":"2026-10-08T19:33:16.923Z","updatedAt":"2026-10-08T21:05:52.349Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107325","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107325","note":"authoritative record"}]},{"id":"0cf25662-fb36-4239-ab16-1188b252726d","slug":"cve-2026-107225","externalId":"CVE-2026-107225","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107225 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.0 to 2.11.0, GetStyle's fill, border, and font extraction predicates check only upper bounds for attacker-controlled style-table indices. File.GetStyle relies on extractStyleCondFuncs predicates that allow negative FillID, BorderID, and FontID values to reach slice indexing. When a crafted styles.xml supplies a negative fillId, borderId, or fontId and the application reads the style, a negative identifier passes the upper-bound-only predicate and becomes a negative slice index, allowing an attacker to panic while reading cell styling. No fixed version is available as of this review.","cveId":"CVE-2026-107225","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.8.0, < 2.11.1-0.20260731010303-ae2113b410e5"],"cwes":["CWE-20","CWE-129"],"tags":["nvd","status:received","osv","osv:ghsa-5h23-36rv-pm65","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/ae2113b410e51f6a141c396a59eda8c42b91bc22","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2367","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-5h23-36rv-pm65","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-5h23-36rv-pm65","type":"advisory","title":"OSV GHSA-5h23-36rv-pm65"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00249,"epssPercentile":0.14856,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T19:17:35.333Z","addedAt":"2026-10-07T20:39:40.446Z","updatedAt":"2026-10-08T21:05:43.774Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107225","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107225","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-5H23-36RV-PM65"}]},{"id":"640be0d8-6e28-4d6d-9edd-9b2c5a32accd","slug":"cve-2026-107222","externalId":"CVE-2026-107222","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107222 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.7.0 to 2.11.0, conditional-format extraction indexes required child slices or dereferences an optional colorScale child without validating malformed rule structure. GetConditionalFormats reaches extractCondFmtCellIs and also indexes ColorScale.Cfvo, DataBar.Cfvo, and DataBar.Color without complete structural checks. When a crafted worksheet supplies a cellIs, dataBar, or colorScale rule missing expected children and the application calls GetConditionalFormats, missing formula, color, value-object, or colorScale data reaches an out-of-range index or nil dereference, allowing an attacker to panic and terminate an unprotected process. No fixed version is available as of this review.","cveId":"CVE-2026-107222","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.7.0, < 2.11.1-0.20260812075026-be7a16390fa6"],"cwes":["CWE-129","CWE-476"],"tags":["nvd","status:received","osv","osv:ghsa-rxcj-4pj5-74gr","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/be7a16390fa69c71d3ca618c741d1a2b5ed362cd","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2375","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-rxcj-4pj5-74gr","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-rxcj-4pj5-74gr","type":"advisory","title":"OSV GHSA-rxcj-4pj5-74gr"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00249,"epssPercentile":0.14856,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T19:17:34.800Z","addedAt":"2026-10-07T20:39:40.424Z","updatedAt":"2026-10-08T21:05:43.640Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107222","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107222","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-RXCJ-4PJ5-74GR"}]},{"id":"59914c3f-ff93-4161-bf43-62be395a695f","slug":"cve-2026-107220","externalId":"CVE-2026-107220","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107220 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.7.1 to 2.11.0, mergeCellsParser leaves the cached rectangle empty for an empty mergeCell ref and then passes that empty slice to cellInRange without a length check. GetCellValue reaches mergeCellsParser, which passes an empty rectangle derived from the mergeCell ref attribute into cellInRange. When a crafted worksheet contains an empty mergeCell ref and a non-streaming cell API reads the worksheet, cellInRange indexes four positions in an empty slice, allowing an attacker to panic on the first affected cell operation. No fixed version is available as of this review.","cveId":"CVE-2026-107220","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.7.1, < 2.11.1-0.20260820023833-99903a3240e5"],"cwes":["CWE-125","CWE-129"],"tags":["nvd","status:received","osv","osv:ghsa-g27h-8qhm-6pff","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/99903a3240e58a47ff28fb8e05a03bd9d496ec24","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2379","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-g27h-8qhm-6pff","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-g27h-8qhm-6pff","type":"advisory","title":"OSV GHSA-g27h-8qhm-6pff"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00244,"epssPercentile":0.14304,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T19:17:34.447Z","addedAt":"2026-10-07T20:39:40.409Z","updatedAt":"2026-10-08T21:05:43.563Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107220","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107220","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-G27H-8QHM-6PFF"}]},{"id":"a53102b8-7335-44b7-9d5f-98eadc40a7e8","slug":"cve-2026-107218","externalId":"CVE-2026-107218","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107218 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.10.1 to 2.11.0, RIGHT validates the requested length with UTF-16 code-unit counts but slices a rune array using Unicode code-point counts. RIGHT reaches leftRight through CalcCellValue, where countUTF16String validates one unit but utf8.RuneCountInString supplies the slice index in another. When RIGHT evaluates supplementary-plane text with a requested character count between the rune count and UTF-16 code-unit count, the inconsistent units produce a negative rune-slice index, allowing an attacker to panic during formula evaluation. No fixed version is available as of this review.","cveId":"CVE-2026-107218","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.10.1, < 2.11.1-0.20260908032718-ecd99d761fe0"],"cwes":["CWE-129"],"tags":["nvd","status:received","osv","osv:ghsa-8jjq-8j9w-m2v6","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/ecd99d761fe0489f1ed308e2f7dc2e0502d1a396","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2390","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-8jjq-8j9w-m2v6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-8jjq-8j9w-m2v6","type":"advisory","title":"OSV GHSA-8jjq-8j9w-m2v6"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00292,"epssPercentile":0.19921,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T19:17:34.120Z","addedAt":"2026-10-07T20:39:40.393Z","updatedAt":"2026-10-08T21:05:43.505Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107218","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107218","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-8JJQ-8J9W-M2V6"}]},{"id":"8a2bd89f-517c-4cd3-8e90-391e6dfc0b4d","slug":"cve-2026-107217","externalId":"CVE-2026-107217","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107217 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error. ColumnNameToNumber accepts the overflowing name VGWQHXLSDVIKWV, after which checkSheetR0 and xlsxWorksheet.checkRow use the wrapped column value as an index. When a crafted worksheet uses an overflowing column name in a row normalized by checkSheetR0 or checkRow, the wrapped zero column becomes a negative slice index during worksheet normalization, allowing an attacker to panic and terminate the calling process. No fixed version is available as of this review.","cveId":"CVE-2026-107217","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.0.0, < 2.11.1-0.20260910071107-696050fbf14e","pkg:golang/github.com/xuri/excelize >= 1.1.0, <= 1.4.1"],"cwes":["CWE-129","CWE-190"],"tags":["nvd","status:received","osv","osv:ghsa-c85p-xxjj-2r75","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/696050fbf14e74e96a58eef2b16aaf72f381a6a8","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2394","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-c85p-xxjj-2r75","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-c85p-xxjj-2r75","type":"advisory","title":"OSV GHSA-c85p-xxjj-2r75"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00335,"epssPercentile":0.24787,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T19:17:33.957Z","addedAt":"2026-10-07T20:39:40.386Z","updatedAt":"2026-10-08T21:05:43.486Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107217","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107217","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-C85P-XXJJ-2R75"}]},{"id":"d0163d69-5bad-499b-89ca-97a914b7e522","slug":"cve-2026-107211","externalId":"CVE-2026-107211","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107211 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks. extractPivotTableFields uses getPivotCacheFieldsName output while processing GetPivotTables and trusts the dataField fld attribute as an index. When a crafted workbook supplies a pivot-field count mismatch or an out-of-range dataField fld value before GetPivotTables is called, the unchecked index causes a Go slice-bounds panic that escapes the library, allowing an attacker to crash the process or request worker. No fixed version is available as of this review.","cveId":"CVE-2026-107211","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.8.1, < 2.11.1-0.20261003002531-6258dcebc4e2"],"cwes":["CWE-129"],"tags":["nvd","status:received","osv","osv:ghsa-mx22-3794-2vpv","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/6258dcebc4e2a2aed985c38a08098dfd908521d1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2435","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-mx22-3794-2vpv","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-mx22-3794-2vpv","type":"advisory","title":"OSV GHSA-mx22-3794-2vpv"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107211","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00291,"epssPercentile":0.19899,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T18:17:18.490Z","addedAt":"2026-10-07T18:39:31.663Z","updatedAt":"2026-10-08T21:05:43.349Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107211","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107211","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-MX22-3794-2VPV"}]},{"id":"41e41045-fde8-47d7-b9fc-8134c80c87d7","slug":"ghsa-2r3x-4mrv-mcxf","externalId":"GHSA-2r3x-4mrv-mcxf","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Vyper: Memory corruption using function calls within tuples / nested calls","description":"### Impact\nWhen performing a function call inside a tuple or as an argument inside another function call, there is a memory corruption issue that occurs because of an incorrect pointer to the the tip of the stack.\n\nExample code:\n```python\n@internal\ndef _foo(a: uint256, b: uint256, c: uint256) -> (uint256, uint256, uint256, uint256, uint256):\n    return 1, a, b, c, 5\n\n@internal\ndef _foo2() -> uint256:\n    a: uint256[10] = [6,7,8,9,10,11,12,13,15,16]\n    return 4\n\n@external\ndef foo() -> (uint256, uint256, uint256, uint256, uint256):\n    return self._foo(2, 3, self._foo2())\n```\n\nPlease see #2186 for further information\n\n### Patches\nThis problem was fixed in #2186, and released as a part of [`v0.2.6`](https://github.com/vyperlang/vyper/releases/tag/v0.2.6).","cveId":null,"cvssScore":null,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","severity":"medium","vendor":"PyPI","product":"vyper","affectedVersions":["pkg:pypi/vyper < 0.2.6"],"cwes":["CWE-129"],"tags":["osv","osv:ghsa-2r3x-4mrv-mcxf","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-2r3x-4mrv-mcxf","type":"advisory","title":"OSV GHSA-2r3x-4mrv-mcxf"},{"url":"https://github.com/vyperlang/vyper/security/advisories/GHSA-2r3x-4mrv-mcxf","type":"other","title":"OSV web"},{"url":"https://github.com/vyperlang/vyper/pull/2186","type":"other","title":"OSV web"},{"url":"https://github.com/vyperlang/vyper/commit/74ba67d4bec5f8be4f05759e37d2bfb1463e0441","type":"other","title":"OSV web"},{"url":"https://github.com/vyperlang/vyper","type":"vendor","title":"OSV package"},{"url":"https://github.com/vyperlang/vyper/releases/tag/v0.2.6","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T15:22:29.000Z","addedAt":"2026-10-06T18:41:23.659Z","updatedAt":"2026-10-06T18:41:23.659Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-2r3x-4mrv-mcxf"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-2r3x-4mrv-mcxf"}]},{"id":"cf252e72-d271-4bea-9cb7-dc88624c9033","slug":"cve-2026-93321","externalId":"CVE-2026-93321","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93321 — A malicious frontend can submit an LLB definition that causes buildkitd\nto panic and terminate, interrupting all builds running on that daemon.","description":"A malicious frontend can submit an LLB definition that causes buildkitd\nto panic and terminate, interrupting all builds running on that daemon.","cveId":"CVE-2026-93321","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-129"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/moby/buildkit/releases/tag/v0.33.1","type":"advisory","title":"security@docker.com"},{"url":"https://github.com/moby/buildkit/security/advisories/GHSA-fjj4-h6vf-m9hj","type":"advisory","title":"security@docker.com"}],"epssScore":0.00155,"epssPercentile":0.04047,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T22:16:58.960Z","addedAt":"2026-10-05T23:50:40.445Z","updatedAt":"2026-10-06T15:50:58.844Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93321","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93321","note":"authoritative record"}]},{"id":"e2d1547e-472c-43b2-b43d-8c6c312189ec","slug":"cve-2026-93322","externalId":"CVE-2026-93322","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93322 — A malicious frontend can submit an LLB definition that causes buildkitd\nto panic and terminate, interrupting all builds running on that daemon.","description":"A malicious frontend can submit an LLB definition that causes buildkitd\nto panic and terminate, interrupting all builds running on that daemon.","cveId":"CVE-2026-93322","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-129"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/moby/buildkit/releases/tag/v0.33.1","type":"advisory","title":"security@docker.com"},{"url":"https://github.com/moby/buildkit/security/advisories/GHSA-cv6p-7w7g-xjwq","type":"advisory","title":"security@docker.com"}],"epssScore":0.00125,"epssPercentile":0.0192,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T18:17:39.490Z","addedAt":"2026-10-05T19:50:42.678Z","updatedAt":"2026-10-06T15:50:57.960Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93322","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93322","note":"authoritative record"}]},{"id":"e5255ad5-7e35-4dd1-938f-c823f95f6b50","slug":"cve-2026-20527","externalId":"CVE-2026-20527","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-20527 — In Modem, there is a possible system crash due to a missing bounds check.","description":"In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01864925 / MOLY01210562; Issue ID: MSV-8303.","cveId":"CVE-2026-20527","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"mediatek","product":"mt2716 firmware","affectedVersions":[],"cwes":["CWE-129"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.mediatek.com/product-security-bulletin/October-2026","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00204,"epssPercentile":0.09456,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T02:16:51.397Z","addedAt":"2026-10-05T03:50:40.205Z","updatedAt":"2026-10-08T16:39:34.709Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20527","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-20527","note":"authoritative record"}]},{"id":"b4bba59a-46cf-4c40-bfbc-38c19c7fd915","slug":"cve-2026-47533","externalId":"CVE-2026-47533","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-47533 — NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validat…","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cveId":"CVE-2026-47533","cvssScore":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-129"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5861","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47533","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47533","type":"advisory","title":"psirt@nvidia.com"}],"epssScore":0.00142,"epssPercentile":0.0302,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:17:20.157Z","addedAt":"2026-09-30T17:50:48.022Z","updatedAt":"2026-10-01T05:50:42.741Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47533","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-47533","note":"authoritative record"}]},{"id":"c2685d5b-bf01-4ff9-8fa8-61d61a8c7000","slug":"cve-2026-47525","externalId":"CVE-2026-47525","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-47525 — NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validat…","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cveId":"CVE-2026-47525","cvssScore":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-129"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5861","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47525","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47525","type":"advisory","title":"psirt@nvidia.com"}],"epssScore":0.00142,"epssPercentile":0.03019,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:17:18.833Z","addedAt":"2026-09-30T17:50:47.978Z","updatedAt":"2026-10-02T05:50:39.481Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47525","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-47525","note":"authoritative record"}]},{"id":"ab26bdc3-6d99-4646-922c-ce87ee0475ee","slug":"cve-2026-47507","externalId":"CVE-2026-47507","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-47507 — NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds array …","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds array access. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cveId":"CVE-2026-47507","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-129"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5861","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47507","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47507","type":"advisory","title":"psirt@nvidia.com"}],"epssScore":0.00146,"epssPercentile":0.03338,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:17:15.907Z","addedAt":"2026-09-30T17:50:47.889Z","updatedAt":"2026-10-01T05:50:42.598Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47507","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-47507","note":"authoritative record"}]},{"id":"f84b5734-7625-4d77-8ad8-b5d6e590ffd8","slug":"cve-2026-102511","externalId":"CVE-2026-102511","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102511 — Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacke…","description":"Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection \naddress was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices\nwill open its ADS session, including any configured route credentials, to that host.\n\nAdditionally, discovery listeners in both implementations can be disabled by a single malformed datagram:\n- In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported.\n- In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response.\n- The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.\n\nExploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.\n\nThis issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it.","cveId":"CVE-2026-102511","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-129","CWE-248","CWE-835","CWE-940"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/g692j4fklrbo80stjr5ll8xghrwszthf","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/30/7","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00177,"epssPercentile":0.06699,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T09:17:14.467Z","addedAt":"2026-09-30T09:50:38.963Z","updatedAt":"2026-09-30T17:50:47.176Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102511","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102511","note":"authoritative record"}]},{"id":"9a38bfaf-3943-4f8b-ad81-eb5722fe868e","slug":"cve-2026-102510","externalId":"CVE-2026-102510","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102510 — Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementati…","description":"Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,\ncausing a denial of service.\n\nThe individual defects are:\n- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).\n- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.\n- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.\n- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.\n- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by  CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 .\n\nAdditionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as \nadditional, independent protocol messages.\n\nThis issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue.","cveId":"CVE-2026-102510","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-129","CWE-190","CWE-674","CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/lw66k49p1jf7w0p7h6yg6jqvysborxrs","type":"advisory","title":"security@apache.org"}],"epssScore":0.00328,"epssPercentile":0.23835,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T09:17:14.293Z","addedAt":"2026-09-30T09:50:38.957Z","updatedAt":"2026-09-30T17:50:47.170Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102510","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102510","note":"authoritative record"}]},{"id":"890463af-a0ef-485f-9afd-a69e559c3280","slug":"cve-2026-102822","externalId":"CVE-2026-102822","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102822 — Russh is a Rust SSH client and server library.","description":"Russh is a Rust SSH client and server library. Prior to 0.63.1, a connection configured to permit mac=none can negotiate it with a MAC-requiring CTR or CBC block cipher because the selection logic validates needs_mac() only when MAC selection fails. A remote peer can then send a packet with a decrypted length of zero, causing russh/src/cipher/mod.rs to shrink the previously read block before indexing buffer.buffer[16..], which panics and terminates the connection task. This issue is fixed in version 0.63.1.","cveId":"CVE-2026-102822","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"low","vendor":"crates.io","product":"russh","affectedVersions":["pkg:cargo/russh < 0.63.1"],"cwes":["CWE-129"],"tags":["nvd","status:deferred","osv","osv:ghsa-p8qx-h547-fjw9","ecosystem:crates.io"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Eugeny/russh/commit/2885385abfee279092a41d80c6cb6ac367353159","type":"other","title":"OSV web"},{"url":"https://github.com/Eugeny/russh/releases/tag/v0.63.1","type":"other","title":"OSV web"},{"url":"https://github.com/Eugeny/russh/security/advisories/GHSA-p8qx-h547-fjw9","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-p8qx-h547-fjw9","type":"advisory","title":"OSV GHSA-p8qx-h547-fjw9"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102822","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/Eugeny/russh","type":"vendor","title":"OSV package"}],"epssScore":0.00327,"epssPercentile":0.23707,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T19:17:24.190Z","addedAt":"2026-09-29T19:50:42.337Z","updatedAt":"2026-10-01T01:54:20.082Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102822","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102822","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-P8QX-H547-FJW9"}]},{"id":"d829ff08-1da9-4d56-b90e-2117f9f92bf5","slug":"cve-2026-100836","externalId":"CVE-2026-100836","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100836 — Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to va…","description":"Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid mesh certificate can trigger a runtime panic by submitting a short base64-encoded ciphertext, causing log spam and request failures without crashing the process.","cveId":"CVE-2026-100836","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"Go","product":"github.com/edgelesssys/contrast","affectedVersions":["pkg:golang/github.com/edgelesssys/contrast < 1.21.0"],"cwes":["CWE-129"],"tags":["nvd","status:received","osv","osv:go-2026-5864","ecosystem:go","osv:ghsa-3ccm-4qq2-5wrp","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/edgelesssys/contrast/commit/d6584fbff816037472034f7ad6e08cdbab1d870d"],"references":[{"url":"https://github.com/edgelesssys/contrast/security/advisories/GHSA-3ccm-4qq2-5wrp","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.vulncheck.com/advisories/edgeless-systems-contrast-through-1.20.0-denial-of-service-via-ciphertextcontainer","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://osv.dev/vulnerability/GO-2026-5864","type":"advisory","title":"OSV GO-2026-5864"},{"url":"https://github.com/edgelesssys/contrast/commit/d6584fbff816037472034f7ad6e08cdbab1d870d","type":"other","title":"OSV web"},{"url":"https://github.com/edgelesssys/contrast/releases/tag/v1.21.0","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-3ccm-4qq2-5wrp","type":"advisory","title":"OSV GHSA-3ccm-4qq2-5wrp"},{"url":"https://github.com/edgelesssys/contrast","type":"vendor","title":"OSV package"}],"epssScore":0.00147,"epssPercentile":0.03393,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-27T02:17:21.797Z","addedAt":"2026-09-27T03:50:37.836Z","updatedAt":"2026-09-28T17:50:40.856Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100836","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100836","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GO-2026-5864"}]},{"id":"12ecc676-d91a-4593-8bf7-a76edaba05f9","slug":"cve-2026-100654","externalId":"CVE-2026-100654","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100654 — vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/chat/completions endpoints but…","description":"vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/chat/completions endpoints but validates only that the values are integers, not that each token id is within the model vocabulary/logits range. When min_tokens > 0, the stop token ids are used as logits indices to suppress stop tokens, so an out-of-range id reaches a CUDA indexing operation (index_put_) and triggers a device-side assertion. An authenticated API user can send a single malformed completion request that returns 500 Internal Server Error and puts EngineCore into a fatal state, causing subsequent requests to fail until the service is restarted (denial of service).","cveId":"CVE-2026-100654","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"vllm","product":"vllm","affectedVersions":["< 0.29.0"],"cwes":["CWE-129"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-v5gm-qgmv-gc6c","type":"vendor","title":"Mitigation"},{"url":"https://www.vulncheck.com/advisories/vllm-before-0.29.0-denial-of-service-via-out-of-range-stop-token-ids","type":"advisory","title":"Third Party Advisory"}],"epssScore":0.00314,"epssPercentile":0.22265,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-26T14:16:48.100Z","addedAt":"2026-09-26T15:50:38.100Z","updatedAt":"2026-10-07T18:39:30.166Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100654","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100654","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":154,"totalPages":8,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:54:20.618Z","durationMs":30,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-129"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}