{"success":true,"data":{"threats":[{"id":"3a20c437-5862-48ed-b845-2ce2d6cd0b73","slug":"cve-2026-96207","externalId":"CVE-2026-96207","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-96207 — Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.","description":"Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.","cveId":"CVE-2026-96207","cvssScore":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96207","type":"advisory","title":"secure@microsoft.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T23:17:05.583Z","addedAt":"2026-10-09T01:06:19.201Z","updatedAt":"2026-10-09T01:06:19.201Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96207","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-96207","note":"authoritative record"}]},{"id":"c582ea72-9b9c-4d04-af13-eb75ce1e8d81","slug":"cve-2026-84032","externalId":"CVE-2026-84032","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84032 — IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certificate validation.","description":"IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certificate validation.","cveId":"CVE-2026-84032","cvssScore":5.6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288627","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:32.900Z","addedAt":"2026-10-08T23:06:40.514Z","updatedAt":"2026-10-08T23:06:40.514Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84032","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84032","note":"authoritative record"}]},{"id":"209432fa-9645-4dbf-8802-31296c0c49b6","slug":"cve-2026-107318","externalId":"CVE-2026-107318","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107318 — @fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server.","description":"@fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server. In versions prior to 12.7.0, all of the built-in HTTPS transports override the secure default and set rejectUnauthorized to false, so the proxy does not verify the TLS certificate of the upstream even when the application points it at an https upstream in the default configuration. An on-path network attacker can therefore impersonate the configured HTTPS upstream, read the credentials and request bodies the proxy forwards, and return forged responses that the application trusts. The issue is fixed in @fastify/reply-from 12.7.0, and users should upgrade to 12.7.0 or later. As a workaround, pass an explicit rejectUnauthorized true on the transport, supply an already configured undici instance, or use the undici global agent.","cveId":"CVE-2026-107318","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","type":"advisory","title":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"url":"https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-j425-jw94-m29r","type":"advisory","title":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:51.807Z","addedAt":"2026-10-08T23:06:39.424Z","updatedAt":"2026-10-08T23:06:39.424Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107318","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107318","note":"authoritative record"}]},{"id":"ec369b23-f0d1-4fd6-ad5e-3796b13397ff","slug":"cve-2026-95210","externalId":"CVE-2026-95210","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-95210 — Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.","description":"Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.","cveId":"CVE-2026-95210","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"http://gnutls.com/","type":"advisory","title":"cve@mitre.org"},{"url":"https://gist.github.com/lkloliver/4aad23689202720c4068f43b3c6069c7","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/lkloliver/poc/tree/main/CVE-2026-95210","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:18:33.370Z","addedAt":"2026-10-08T18:39:31.991Z","updatedAt":"2026-10-08T23:06:39.051Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95210","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-95210","note":"authoritative record"}]},{"id":"72c8ccb8-2baa-4c7f-940c-acdc8eaeebf9","slug":"cve-2026-95208","externalId":"CVE-2026-95208","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-95208 — An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service …","description":"An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service (DoS) via providing crafted Certificate Authority certificates, leading to valid certificates without SAN to be incorrectly rejected by wolfSSL-based TLS clients.","cveId":"CVE-2026-95208","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"http://wolfssl.com/","type":"advisory","title":"cve@mitre.org"},{"url":"https://gist.github.com/lkloliver/14edf8bbfbf5769949b85c7f5cc2eba2","type":"advisory","title":"cve@mitre.org"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:18:01.420Z","addedAt":"2026-10-08T16:39:36.079Z","updatedAt":"2026-10-08T23:06:38.530Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95208","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-95208","note":"authoritative record"}]},{"id":"20c2f3b0-ad07-41e1-b247-43fd1110f249","slug":"cve-2026-107587","externalId":"CVE-2026-107587","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107587 — Improper certificate validation in the webmail of Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to hav…","description":"Improper certificate validation in the webmail of Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to have S/MIME-encrypted mail that the account later sends to another correspondent also encrypted to the attacker's key. When its recipient opened a signed message, the webmail kept the signer's certificate for encrypting replies whether or not the server found its chain trusted, under the first e-mail address the certificate listed rather than the message's From address, and beside any certificate already held for that address. Encrypted mail later sent from the webmail to that address was encrypted to every certificate held for it, so a holder of the kept certificate's key who obtains a copy of such a message can read it.","cveId":"CVE-2026-107587","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/66","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T12:17:16.937Z","addedAt":"2026-10-08T12:39:41.418Z","updatedAt":"2026-10-08T23:06:37.838Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107587","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107587","note":"authoritative record"}]},{"id":"a4803f1a-7d86-4eff-934e-68bd7134285c","slug":"cve-2026-87425","externalId":"CVE-2026-87425","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87425 — An unauthenticated remote attacker can modify the TLS client trust store in Brocade ASCG versions before 3.5.0.","description":"An unauthenticated remote attacker can modify the TLS client trust store in Brocade ASCG versions before 3.5.0. By supplying an unauthorized Certificate Authority (CA) certificate to an unauthenticated management interface, the attacker can cause the system to trust unauthorized certificates, potentially enabling Man-in-the-Middle (MITM) attacks against outbound communications with managed switches and peer nodes.","cveId":"CVE-2026-87425","cvssScore":7.6,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/38392","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00104,"epssPercentile":0.00965,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T07:16:33.140Z","addedAt":"2026-10-08T08:39:29.350Z","updatedAt":"2026-10-08T21:05:47.694Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87425","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87425","note":"authoritative record"}]},{"id":"77a34044-43b7-4aa2-8c51-111867b73ec8","slug":"cve-2026-92543","externalId":"CVE-2026-92543","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-92543 — Docker Engine classifies a registry hostname as insecure using an any-match DNS check.","description":"Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.","cveId":"CVE-2026-92543","cvssScore":7.6,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295","CWE-319"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/moby/moby/security/advisories/GHSA-7cfq-22r6-qp73","type":"advisory","title":"security@docker.com"}],"epssScore":0.00087,"epssPercentile":0.00346,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:17:02.727Z","addedAt":"2026-10-07T18:39:31.596Z","updatedAt":"2026-10-08T21:05:43.280Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92543","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-92543","note":"authoritative record"}]},{"id":"62a4530c-c30a-4e10-99c6-f1759085e17e","slug":"cve-2026-63697","externalId":"CVE-2026-63697","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-63697 — Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability.","description":"Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.","cveId":"CVE-2026-63697","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000515843/dsa-2026-324-security-update-for-dell-system-update-dsu-vulnerabilities","type":"advisory","title":"security_alert@emc.com"}],"epssScore":0.00289,"epssPercentile":0.19643,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:15.447Z","addedAt":"2026-10-06T20:39:32.518Z","updatedAt":"2026-10-09T03:06:16.903Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63697","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-63697","note":"authoritative record"}]},{"id":"ab8b3386-22f7-467d-a9d6-fd7d00cebf46","slug":"cve-2026-67270","externalId":"CVE-2026-67270","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-67270 — Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server compon…","description":"Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials.","cveId":"CVE-2026-67270","cvssScore":8.2,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","type":"advisory","title":"security_alert@emc.com"}],"epssScore":0.00117,"epssPercentile":0.01537,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T16:17:09.580Z","addedAt":"2026-10-06T17:50:42.492Z","updatedAt":"2026-10-09T03:06:16.492Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67270","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-67270","note":"authoritative record"}]},{"id":"f4b32eea-5357-4120-9d9c-e4cb1c085ce1","slug":"cve-2026-105794","externalId":"CVE-2026-105794","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105794 — MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust.","description":"MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients using the OpenSSL or QuicTLS TLS backend do not properly verify that a server certificate matches the intended target server hostname. An on-path attacker can therefore present a certificate that does not match the intended target hostname and spoof the server in a man-in-the-middle attack. The Schannel backend is not affected. This issue is fixed in versions 2.4.20, 2.5.11, and 2.6.1.","cveId":"CVE-2026-105794","cvssScore":9.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/microsoft/msquic/commit/0591586443cc73a2d2cfb679527d91a144b4a412","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/commit/508e811370df93e2ad848f5c78347d4fe4f65a91","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/commit/90fd45498bf9b506b8556fb407088688474d6c81","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/commit/a01333cf7c2659cce0ff03ef3f21e1ff15bb5b83","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/pull/6274","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/pull/6275","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/pull/6276","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/pull/6277","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/releases/tag/v2.4.20","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/releases/tag/v2.5.11","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/releases/tag/v2.6.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/security/advisories/GHSA-w5f4-fx9m-m4q7","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.01001,"epssPercentile":0.61706,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T15:17:16.260Z","addedAt":"2026-10-06T15:51:00.418Z","updatedAt":"2026-10-06T18:39:27.039Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105794","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105794","note":"authoritative record"}]},{"id":"8026033c-b302-441f-89ef-77292b0e556b","slug":"cve-2026-105223","externalId":"CVE-2026-105223","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105223 — maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfi…","description":"maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic credentials and tamper with WebSocket or REST API traffic.","cveId":"CVE-2026-105223","cvssScore":9.1,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/maclof/kubernetes-client","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/maclof/kubernetes-client/blob/0.31.0/src/Client.php#L309-L312","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/maclof/kubernetes-client/commit/924c0b935fa538ed6b4b0948127609e99d0e6f34","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/maclof/kubernetes-client/issues/135","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/maclof/kubernetes-client/releases/tag/0.32.0","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/maclof-kubernetes-client-0.17.0-before-0.32.0-disabled-tls-certificate-verification","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00199,"epssPercentile":0.08857,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T01:16:28.480Z","addedAt":"2026-10-05T01:50:40.071Z","updatedAt":"2026-10-06T17:50:41.938Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105223","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105223","note":"authoritative record"}]},{"id":"820e98c1-c996-44d6-ae6e-a64e0ccbbbd8","slug":"cve-2026-105222","externalId":"CVE-2026-105222","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105222 — The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_ve…","description":"The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.","cveId":"CVE-2026-105222","cvssScore":9.1,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/alexpechkarev/google-maps","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/alexpechkarev/google-maps/blob/v12.14/src/WebService.php#L267-L269","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/alexpechkarev/google-maps/blob/v12.16/src/config/googlemaps.php#L28","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/alexpechkarev/google-maps/issues/123","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/alexpechkarev-google-maps-through-12.16-disabled-tls-certificate-verification-via-ssl-verify-peer","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00189,"epssPercentile":0.07761,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-04T23:16:59.917Z","addedAt":"2026-10-04T23:50:40.096Z","updatedAt":"2026-10-06T17:50:41.932Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105222","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105222","note":"authoritative record"}]},{"id":"11ffb52c-f93d-41d4-a051-5dda42b2e584","slug":"cve-2026-105221","externalId":"CVE-2026-105221","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105221 — The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic be…","description":"The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.","cveId":"CVE-2026-105221","cvssScore":9.1,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/defunkt/gist","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/defunkt/gist/blob/v6.0.0/lib/gist.rb#L466-L468","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/defunkt/gist/commit/07ccc1a6d46e9d36f0e85d0b1c5d795890ae6bcf","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/defunkt/gist/issues/373","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gist-rubygem-before-6.1.0-disabled-tls-certificate-verification","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00178,"epssPercentile":0.06777,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-04T23:16:59.770Z","addedAt":"2026-10-04T23:50:40.089Z","updatedAt":"2026-10-06T17:50:41.927Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105221","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105221","note":"authoritative record"}]},{"id":"0ee39231-5d7f-4850-85c6-fd982e4ed3b9","slug":"cve-2026-105218","externalId":"CVE-2026-105218","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105218 — gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to imper…","description":"gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.","cveId":"CVE-2026-105218","cvssScore":9.1,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/go-pay/gopay","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/go-pay/gopay/blob/v1.5.118/pkg/xhttp/client.go#L15-L37","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/go-pay/gopay/commit/f6df04fd4f64a2ad2c303ba063b6502bfdd259fd","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/go-pay/gopay/issues/540","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gopay-before-1.5.119-disabled-tls-certificate-verification-in-xhttp-client","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00163,"epssPercentile":0.05055,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-04T18:16:34.630Z","addedAt":"2026-10-04T19:50:39.955Z","updatedAt":"2026-10-06T17:50:41.911Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105218","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105218","note":"authoritative record"}]},{"id":"2278125c-2bd4-44a4-bc1f-d5ed2347a9bd","slug":"cve-2026-105217","externalId":"CVE-2026-105217","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105217 — Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to ca…","description":"Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker.","cveId":"CVE-2026-105217","cvssScore":2.3,"cvssVector":"CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Cockpit-HQ/Cockpit","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Cockpit-HQ/Cockpit/blob/2.14.0/cron.php#L70-L102","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Cockpit-HQ/Cockpit/commit/c611492adc17362578faa97f9c30b41e6c16e040","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Cockpit-HQ/Cockpit/issues/318","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/cockpit-cms-2.12.0-before-2.14.1-disabled-tls-verification-via-cron-php","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00103,"epssPercentile":0.00898,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-04T18:16:34.433Z","addedAt":"2026-10-04T19:50:39.948Z","updatedAt":"2026-10-06T15:50:56.709Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105217","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105217","note":"authoritative record"}]},{"id":"1d78622a-c4aa-4f12-9eaa-894b94bd5b3a","slug":"cve-2026-105216","externalId":"CVE-2026-105216","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105216 — go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the s…","description":"go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.","cveId":"CVE-2026-105216","cvssScore":9.1,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/micro/go-micro","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/micro/go-micro/blob/v5.30.0/internal/util/tls/tls.go#L43-L67","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/micro/go-micro/commit/c7657f73f45cf839e643db10f28703eeab7299c3","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/micro/go-micro/issues/2963","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/go-micro-before-6.0.0-disabled-tls-certificate-verification-via-tls-config-helper","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00194,"epssPercentile":0.08319,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-04T18:16:34.287Z","addedAt":"2026-10-04T19:50:39.940Z","updatedAt":"2026-10-06T17:50:41.905Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105216","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105216","note":"authoritative record"}]},{"id":"e6a445e4-b29a-4a33-a79e-2350c9fba209","slug":"cve-2026-71889","externalId":"CVE-2026-71889","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-71889 — In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.…","description":"In Bouncy Castle for Java before 1.86, neither copy of PKIXCertPathReviewer - org.bouncycastle.pkix.jcajce.PKIXCertPathReviewer nor the legacy org.bouncycastle.x509.PKIXCertPathReviewer - applied X.509 name constraints to the end-entity certificate. checkNameConstraints walked the path with a loop bound of index greater than zero, which is the bound the CA-only steps require, but index zero is the target certificate under the standard CertPath ordering, so the permitted and excluded subtree checks of RFC 5280 sec. 6.1.3 (b) and (c) never ran against the leaf's subject DN or its subjectAltName. A chain whose leaf violated a NameConstraints extension imposed by its own issuing CA therefore reported isValidCertPath() true with an empty error list, while CertPathValidator.getInstance(\"PKIX\", \"BC\"), which shares no code with the reviewer, rejected the identical chain against the identical trust anchor. An application using the reviewer to make the trust decision rather than for diagnostics alongside a real validation accepted a certificate the constrained CA was never authorised to issue. Both copies now check every certificate in the path including the target, waive the sec. 4.2.1.10 self-issued exemption for the final certificate as sec. 6.1.3 requires, and skip the sec. 6.1.4 (g) constraint-accumulation step for the target. This issue also affects Bouncy Castle for Java LTS before 2.73.13, which carries only the org.bouncycastle.pkix.jcajce copy of the reviewer. It also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).","cveId":"CVE-2026-71889","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/bcgit/bc-java/commit/06dcff2f51037095de126986285c998e3455ab85","type":"advisory","title":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071889","type":"advisory","title":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epssScore":0.00167,"epssPercentile":0.05412,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-03T09:17:05.437Z","addedAt":"2026-10-03T09:50:39.605Z","updatedAt":"2026-10-06T15:50:56.382Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71889","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-71889","note":"authoritative record"}]},{"id":"d821e2c7-c356-43f9-9a9e-adc4453cfa53","slug":"cve-2026-71885","externalId":"CVE-2026-71885","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-71885 — In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's…","description":"In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored but never parsed or validated, so the end-entity certificate's public key was never required to match signature_key as RFC 9420 sec. 5.3 requires. A party could therefore present another party's certificate as its credential while signing the leaf, and the enclosing KeyPackage, with an unrelated key, and be accepted under that other party's identity through KeyPackage.verify() and the Group leaf-validation path. In a deployment that admits external commits without an independent credential-admission check, an unauthenticated attacker could be admitted under a victim's X.509 identity, evict the victim (resynchronization compares whole credentials rather than signing keys), derive the current epoch, decrypt subsequent group messages, and send messages accepted as the victim. TreeKEM.LeafNode now requires the end-entity certificate's subject public key, in the cipher suite's signature encoding, to equal signature_key for an X.509 credential and rejects the leaf otherwise, including an empty chain or a certificate whose key type does not match the cipher suite; certificate-chain and identity validation to a trust anchor remain the application's responsibility per RFC 9420 sec. 5.3.1. Deployments using only basic credentials are unaffected.","cveId":"CVE-2026-71885","cvssScore":9.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-287","CWE-295"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/bcgit/bc-java/commit/77632a57edf350a7b5751fca1a5052daffa8dab2","type":"advisory","title":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071885","type":"advisory","title":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epssScore":0.00188,"epssPercentile":0.07653,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-03T09:17:04.730Z","addedAt":"2026-10-03T09:50:39.571Z","updatedAt":"2026-10-06T15:50:56.356Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71885","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-71885","note":"authoritative record"}]},{"id":"826670f1-8cec-4830-a3a1-2174680aaf2a","slug":"cve-2026-85088","externalId":"CVE-2026-85088","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85088 — Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift.","description":"Improper Validation of Certificate with Host Mismatch in the C++ and D libraries of Apache Thrift.\n\n\n\nBoth libraries install a default access manager for client sockets — TSSLSocketFactory does so in C++, and the accessManager property does so in D — which compares the peer certificate against the host\n\nname that was connected to. That comparison walks the subjectAltName dNSName entries first and consults the certificate Common Name afterwards. A name that does not match yields a \"skip\" result rather than\n\na rejection, so a certificate whose subjectAltName entries are all present and all non-matching falls through to the Common Name, which can then satisfy the check.\n\n\n\nRFC 6125 section 6.4.4, and RFC 9525 section 2, require that the Common Name is not consulted when a dNSName subjectAltName is present. A certificate carrying subjectAltName entries for one name and a\n\nCommon Name for another is therefore accepted for a connection to the second name.\n\n\n\nExploitation requires an attacker positioned on the network path who holds a certificate that chains to a certificate authority in the client's trust store and whose Common Name matches the connected host\n\nname. Public certificate authorities have not issued on Common Name alone for many years, so this is principally a concern for deployments using a private or enterprise public-key infrastructure.\n\n\n\nThis issue affects the C++ library of Apache Thrift from 0.7.0 through 0.24.0 and the D library from 0.9.0 through 0.24.0. Users should upgrade to 0.25.0.","cveId":"CVE-2026-85088","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295","CWE-297"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/zcgm7lx6037lvgvn87rc1tj3p0zhv371","type":"advisory","title":"security@apache.org"}],"epssScore":0.00215,"epssPercentile":0.10947,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:21.800Z","addedAt":"2026-10-02T13:50:40.776Z","updatedAt":"2026-10-02T19:50:41.377Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85088","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85088","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":321,"totalPages":17,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T03:16:59.928Z","durationMs":39,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-295"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}