{"success":true,"data":{"threats":[{"id":"d9c8b2b2-7cd7-4971-86a0-35842b9a6cd1","slug":"cve-2026-13257","externalId":"CVE-2026-13257","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-13257 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an a…","description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an authenticated user to forge signature requests due to improper verification of data authenticity.","cveId":"CVE-2026-13257","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7289775","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:48.143Z","addedAt":"2026-10-08T16:39:35.856Z","updatedAt":"2026-10-08T21:05:50.156Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13257","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-13257","note":"authoritative record"}]},{"id":"6cac5311-191b-4746-814f-65ab36b9f14c","slug":"cve-2026-103517","externalId":"CVE-2026-103517","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103517 — The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the…","description":"The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying.","cveId":"CVE-2026-103517","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/17179c6d-32e0-4a22-88b4-9768a5f36365/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T11:16:42.613Z","addedAt":"2026-10-08T12:39:41.230Z","updatedAt":"2026-10-08T21:05:47.920Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103517","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103517","note":"authoritative record"}]},{"id":"702241f0-7961-468e-aee9-e9a472f14c1d","slug":"cve-2026-107284","externalId":"CVE-2026-107284","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107284 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a handshake whose Sec-WebSocket-Accept value is missing or invalid but continues into pipeline installation and onOpen delivery. Frames coalesced with the invalid 101 response can be decoded and delivered from a peer that did not prove the handshake, although the request future fails and the channel closes. This issue is fixed in versions 3.0.12 and 2.16.1.","cveId":"CVE-2026-107284","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345","CWE-670"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/75a278550aa9a980009d022fb4e635f9c8738c03","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/ccdcaa627db6d96dcc42105212cb3ba5048bd7f9","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rwhr-j9rv-85f8","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00138,"epssPercentile":0.02723,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:04.483Z","addedAt":"2026-10-07T22:39:36.829Z","updatedAt":"2026-10-08T21:05:45.194Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107284","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107284","note":"authoritative record"}]},{"id":"65a80aa4-a98f-451d-b546-d66234d92ceb","slug":"cve-2026-105818","externalId":"CVE-2026-105818","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105818 — Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under…","description":"Vault's PKI secrets engine ACME server did not restrict certificate identities that ACME challenges do not validate when issuing certificates under the default directory policy. This may allow an ACME client to obtain a certificate containing unverified identity claims, potentially enabling impersonation toward systems that trust certificates issued by the affected Vault PKI mount. This vulnerability (CVE-2026-105818) is fixed in Vault Community Edition 2.1.2, and Vault Enterprise 2.1.2, 1.21.12, 1.20.17, and 1.19.23.","cveId":"CVE-2026-105818","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://discuss.hashicorp.com/t/hcsec-2026-40-vault-pki-acme-default-directory-policy-may-issue-certificates-with-unverified-identities/77812","type":"advisory","title":"security@hashicorp.com"}],"epssScore":0.0008,"epssPercentile":0.0014,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:02.843Z","addedAt":"2026-10-07T22:39:36.752Z","updatedAt":"2026-10-08T23:06:36.972Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105818","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105818","note":"authoritative record"}]},{"id":"dfe7ffbd-dbd8-431d-9e3b-d9ffeda91b85","slug":"cve-2026-61428","externalId":"GHSA-qj9c-59p6-8cgx","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing","description":"## Summary\n\nPraisonAI's AgentMail bot, when run in webhook (or hybrid) mode, starts an aiohttp webhook server bound to `0.0.0.0` and processes inbound `message.received` events **without verifying any signature/HMAC and without authentication**. The sender address and message body are taken directly from the attacker-controlled request body, so any network peer can inject messages into the agent with a spoofed sender (bypassing sender allow/block lists) and have the agent process the content and reply to an attacker-chosen address. Sibling bots (`linear.py`, `whatsapp.py`) fail closed when no secret is configured; AgentMail omits the check entirely. Runtime-confirmed; severity Medium.\n\n## Details\n\n### Affected component\n- Package: `praisonai` 4.6.63. File: `src/praisonai/praisonai/bots/agentmail.py` (`AgentMailBot`, webhook/hybrid mode).\n\n### Vulnerable code / root cause\n\nPath:\n`src/praisonai/praisonai/bots/agentmail.py`\n\nFunction:\n`_start_webhook_mode` / `_handle_email_webhook` / `_handle_message`\n\nSnippet:\n```python\n# _start_webhook_mode: binds all interfaces\nself._webhook_site = web.TCPSite(self._webhook_runner, \"0.0.0.0\", self._webhook_port)\n\n# _handle_email_webhook: no signature/HMAC check, no auth\nbody = await request.json()\nif body.get(\"type\") != \"message.received\":\n    return web.Response(status=200, text=\"OK\")\nasyncio.create_task(self._process_webhook_payload(body))   # dispatch attacker body\nreturn web.Response(status=200, text=\"OK\")\n\n# _handle_message: agent processes content, replies to attacker-controlled sender\nresponse = await self._session.chat(self._agent, sender_id, body, ...)\nawait self.send_message(channel_id=sender_id, ...)\n```\nIssue: attacker-controlled input is the raw webhook JSON (`from`, `extracted_text`, `subject`). The guard that *should* exist is provider signature verification — there is **none** here (no svix/HMAC, no `webhooks_require_verification()` call). The sink is `self._session.chat(self._agent, ...)` (agent invocation) and `send_message(channel_id=sender_id, ...)` (reply to the spoofed sender). Sibling handlers `src/praisonai/praisonai/bots/linear.py` and `bots/whatsapp.py` call `webhooks_require_verification()` and reject when no secret is set — AgentMail does not, so it fails open.\n\n### Attack flow\n1. Operator runs the AgentMail bot in webhook/hybrid mode (documented; binds `0.0.0.0`, default path `/webhook`, default port 8080).\n2. Attacker POSTs a crafted `message.received` event with a spoofed `from` and arbitrary `extracted_text`.\n3. The agent processes the content; any reply is sent to the attacker-chosen `sender_id`.\n\n### Why existing protection is bypassed\nThere is no protection on this handler: no signature verification, no `webhooks_require_verification()` gate, no auth. Sender allow/block lists are bypassed because `from` is attacker-controlled.\n\n### Security boundary\nUnauthenticated network peer → agent message pipeline + reply destination. Crosses the bot's inbound trust boundary (provider webhooks are expected to be signed/authenticated).\n\n## Proof of Concept\n\n### Environment\nReal `AgentMailBot._handle_email_webhook` mounted in a local runtime (`127.0.0.1:18080`); the agent layer is a canary recorder (`/webhook-log`). No real email is sent. Runnable assets: `PraisonAI-Runtime-Repro\\runtime-files\\`.\n\n### Steps to reproduce\n1. `PRAI-03-01-Webhook-Spoofed-Sender`:\n```http\nPOST /webhook HTTP/1.1\nHost: 127.0.0.1:18080\nContent-Type: application/json\n\n{\"type\":\"message.received\",\"data\":{\"from\":\"attacker@evil.example\",\"extracted_text\":\"PRAISONAI_WEBHOOK_INJECT_CANARY_7f3a91 ...\",\"subject\":\"hello\",\"headers\":{}}}\n```\n2. `PRAI-03-02-Agent-Reached-Response`: `GET /webhook-log`.\n\n### Expected result\nThe webhook should reject unsigned/unauthenticated events; spoofed senders should not reach the agent.\n\n### Actual result\n- `POST /webhook` → `200 OK` (no auth/signature).\n- `GET /webhook-log` → `{\"reached_agent\":[{\"sender\":\"attacker@evil.example\",\"content\":\"...PRAISONAI_WEBHOOK_INJECT_CANARY_7f3a91...\",\"source\":\"webhook\"}],\"count\":1}`.\n\n## Impact\nUnauthenticated message injection into the agent; sender spoofing (access-control bypass); agent reply/exfiltration to an attacker-chosen address; prompt-injection surface; LLM cost abuse. If the agent has dangerous tools, escalation via prompt injection is possible.","cveId":"CVE-2026-61428","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","severity":"high","vendor":"PyPI","product":"praisonai","affectedVersions":["pkg:pypi/praisonai < 4.6.78"],"cwes":["CWE-290","CWE-345","CWE-862"],"tags":["osv","osv:ghsa-qj9c-59p6-8cgx","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-qj9c-59p6-8cgx","type":"advisory","title":"OSV GHSA-qj9c-59p6-8cgx"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qj9c-59p6-8cgx","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61428","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-agentmail-before-message-injection-via-webhook","type":"other","title":"OSV web"}],"epssScore":0.00373,"epssPercentile":0.29118,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:06:56.000Z","addedAt":"2026-10-07T18:42:45.500Z","updatedAt":"2026-10-07T18:42:45.500Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61428","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61428","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-qj9c-59p6-8cgx"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-qj9c-59p6-8cgx"}]},{"id":"297b5729-76aa-46ee-afa8-51ff59d9ed6a","slug":"cve-2026-107102","externalId":"CVE-2026-107102","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107102 — This vulnerability exists in the ERP system due to improper validation of payment callback parameters and inadequate authentication controls in API…","description":"This vulnerability exists in the ERP system due to improper validation of payment callback parameters and inadequate authentication controls in API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating the parameter to cause the application to establish an authenticated session for an arbitrary user without valid payment verification.\n\nSuccessful exploitation of this vulnerability could allow the attacker to bypass authentication and gain unauthorized access to other user accounts on the targeted system.","cveId":"CVE-2026-107102","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0430","type":"advisory","title":"vdisclose@cert-in.org.in"}],"epssScore":0.00255,"epssPercentile":0.15714,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T09:17:04.780Z","addedAt":"2026-10-07T10:39:38.696Z","updatedAt":"2026-10-07T20:39:40.074Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107102","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107102","note":"authoritative record"}]},{"id":"598f8e15-d935-4efa-81f5-50d623ab4cd1","slug":"cve-2026-82212","externalId":"CVE-2026-82212","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-82212 — The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate the security token on its payment notification route, accepting the …","description":"The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate the security token on its payment notification route, accepting the request when the target order has no stored token, which allows unauthenticated attackers to mark arbitrary orders as paid, or to mark genuinely paid orders as failed.","cveId":"CVE-2026-82212","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/66df6adb-336c-4660-9a63-5e6e550a2edb/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":0.00131,"epssPercentile":0.02332,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T07:17:01.493Z","addedAt":"2026-10-07T08:39:33.410Z","updatedAt":"2026-10-07T16:39:31.857Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82212","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-82212","note":"authoritative record"}]},{"id":"abb475ad-4239-41be-a75d-48bbd915ddea","slug":"cve-2026-16516","externalId":"CVE-2026-16516","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-16516 — wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange.","description":"wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In ParseECCPubKey() (src/internal.c), the blob's algorithm string is used to derive the curve via NameToId/wcPrimeForId without checking against the negotiated ssh->handshake->pubKeyId, and the RFC 5656 curve identifier string is discarded via GetSkip() rather than compared. An active network man-in-the-middle attacker can substitute a host key blob containing a different ECDSA curve, causing the client to import the key on the wrong curve. Because the attacker controls the private key for the substituted curve, signature verification passes. Exploitation requires an active MitM position and a lax public key check callback (e.g., TOFU, algorithm-name-only check, or fingerprint match against the parsed key).","cveId":"CVE-2026-16516","cvssScore":9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/wolfSSL/wolfssh/commit/31d13697a608fa1bf9eec11aa6eff1503ade836f","type":"advisory","title":"facts@wolfssl.com"},{"url":"https://github.com/wolfSSL/wolfssh/issues/1012","type":"advisory","title":"facts@wolfssl.com"}],"epssScore":0.0015,"epssPercentile":0.03652,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T03:16:58.830Z","addedAt":"2026-10-07T04:39:33.951Z","updatedAt":"2026-10-07T16:39:31.645Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16516","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-16516","note":"authoritative record"}]},{"id":"987229d0-4a5d-4268-8d7b-06518a3176ac","slug":"cve-2026-104850","externalId":"CVE-2026-104850","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104850 — MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients.","description":"MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP server a client connected to decide which authorization server received the client's OAuth credentials. Stored and pre-provisioned credentials were not bound to the authorization server they belong to. A malicious or compromised MCP server could name its own authorization server in its protected resource metadata. Without any user interaction, the client would send that server the `refresh_token` and `client_secret` stored from an earlier sign-in (1.x), or the configured `client_secret` or signed assertion of a bundled non-interactive provider (1.x and 2.x). Only those applications that use the SDK as an MCP client over HTTP with an `authProvider`: your own `OAuthClientProvider`, or the bundled `ClientCredentialsProvider`, `PrivateKeyJwtProvider`, `StaticPrivateKeyJwtProvider` or (2.x) `CrossAppAccessProvider` and that may connect to an MCP server the owners does not fully trust while holding credentials for a legitimate authorization server are affected. `@modelcontextprotocol/sdk` 1.31.0 (1.x) and `@modelcontextprotocol/client` 2.2.0 (2.x) patch the issue. A workaround for those who cannot upgrade is available. 2.0.0 and 2.1.0 already accept `expectedIssuer`. On 1.x, the only workaround is to connect OAuth-enabled clients only to MCP servers you trust.","cveId":"CVE-2026-104850","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":"npm","product":"@modelcontextprotocol/sdk","affectedVersions":["pkg:npm/%40modelcontextprotocol/sdk >= 1.12.0, < 1.31.0","pkg:npm/%40modelcontextprotocol/client >= 2.0.0, < 2.2.0"],"cwes":["CWE-345","CWE-522"],"tags":["nvd","status:received","osv","osv:ghsa-6qxp-vccf-f47h","ecosystem:npm","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/modelcontextprotocol/typescript-sdk/commit/edd12e282620ebf770d67316f19cf91d4112a1bd","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/modelcontextprotocol/typescript-sdk/pull/2887","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/modelcontextprotocol/typescript-sdk/releases/tag/v2.2.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/modelcontextprotocol/typescript-sdk/security/advisories/GHSA-6qxp-vccf-f47h","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-6qxp-vccf-f47h","type":"advisory","title":"OSV GHSA-6qxp-vccf-f47h"},{"url":"https://github.com/modelcontextprotocol/typescript-sdk","type":"vendor","title":"OSV package"}],"epssScore":0.00176,"epssPercentile":0.06479,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T17:17:15.827Z","addedAt":"2026-10-06T17:50:42.536Z","updatedAt":"2026-10-06T20:39:29.874Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104850","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104850","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-6QXP-VCCF-F47H"}]},{"id":"0427964e-a1ec-4299-bb06-aae484e1a91e","slug":"cve-2026-59357","externalId":"CVE-2026-59357","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-59357 — Insufficient verification of data authenticity (CWE-345) in the external OIDC login callback in Cloud Foundry UAA v4.5.0 to v79.6.0 (inclusive) all…","description":"Insufficient verification of data authenticity (CWE-345) in the external OIDC login callback in Cloud Foundry UAA v4.5.0 to v79.6.0 (inclusive) allows an authenticated UAA user to bypass the OAuth authorization-code exchange and establish an authenticated external-OIDC browser session, via submitting a UAA access token or a cross-client ID token as the callback’s id_token parameter.\n\n\n\nThe issue only manifests when a UAA zone is configured with an OIDC identity provider whose issuer exactly matches that zone’s own /oauth/token endpoint (a “self-UAA” OIDC configuration). In this configuration, the callback takes a supplied id_token directly instead of requiring the authorization code exchange, and does not verify that the token was actually issued as an ID token for the specific self-OIDC relying-party client. An attacker holding any valid UAA JWT for themselves — including a plain access token with only uaa.user scope, or a valid ID token issued to an unrelated client such as cf — can present it as the callback’s id_token and be authenticated into a mapped local (“shadow”) account. Because the resulting session is not verified against the originating token’s true audience or user_id, its effective privilege depends entirely on the shadow account’s group memberships, which can include administrative scopes such as clients.write.\n\n\n\nExploitation requires a valid UAA user JWT, a valid browser login state for the target zone, and the presence of a self-referential OIDC provider configuration — this is not a pre-authentication vulnerability, and does not by itself grant privileges beyond those already held by the mapped shadow account.","cveId":"CVE-2026-59357","cvssScore":6.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.cloudfoundry.org/blog/cve-2026-59357-self-uaa-oidc-configuration-allows-jwt-injection-to-establish-unauthorized-sessions/","type":"advisory","title":"security@vmware.com"}],"epssScore":0.00185,"epssPercentile":0.07402,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T07:16:59.253Z","addedAt":"2026-10-06T07:50:40.840Z","updatedAt":"2026-10-06T17:50:42.268Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59357","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-59357","note":"authoritative record"}]},{"id":"4683757f-3414-4d49-8731-e86c5127d500","slug":"cve-2026-105741","externalId":"CVE-2026-105741","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105741 — Langflow is a tool for building and deploying AI-powered agents and workflows.","description":"Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the \"local-only\" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3.","cveId":"CVE-2026-105741","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","severity":"high","vendor":"PyPI","product":"langflow","affectedVersions":["pkg:pypi/langflow >= 1.5.0, < 1.10.3"],"cwes":["CWE-290","CWE-345"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-4f6c-2vvp-gw82","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/langflow-ai/langflow/commit/1f39a4b9d62c9dfa1b21fa7f85e23a180c351b72","type":"other","title":"OSV web"},{"url":"https://github.com/langflow-ai/langflow/commit/94859df33acd70b2a1f816e26d68f5e89a7e5639","type":"other","title":"OSV web"},{"url":"https://github.com/langflow-ai/langflow/pull/13915","type":"other","title":"OSV web"},{"url":"https://github.com/langflow-ai/langflow/releases/tag/v1.10.3","type":"other","title":"OSV web"},{"url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-4f6c-2vvp-gw82","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-4f6c-2vvp-gw82","type":"advisory","title":"OSV GHSA-4f6c-2vvp-gw82"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105741","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/langflow-ai/langflow","type":"vendor","title":"OSV package"}],"epssScore":0.00212,"epssPercentile":0.1053,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T21:16:35.740Z","addedAt":"2026-10-05T21:50:41.187Z","updatedAt":"2026-10-07T18:42:44.973Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105741","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105741","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-4F6C-2VVP-GW82"}]},{"id":"500ef032-71f3-412c-b17d-6f15079476fb","slug":"cve-2026-104805","externalId":"CVE-2026-104805","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104805 — DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup r…","description":"DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration.\n\n\n\n\nThe specific flaw exists within the backup restoration mechanism, which fails to properly validate the paths, file types, integrity, and authenticity of files contained within a restored TGZ archive. The application does not perform file-signature verification before extracting the archive, allowing a specially crafted backup to contain attacker-controlled files.\n\n\n\n\nAn attacker with access to the backup SFTP or other configured repository can therefore provide a malicious TGZ archive that, when restored by the system, may place arbitrary files on the underlying Linux system. Depending on the location and permissions of the extracted files, this behavior can potentially be leveraged to achieve arbitrary code execution with root privileges and compromise the underlying virtual machine.\n\n\n\n\nThe absence of enforced backup passwords further reduces the protection provided by the backup mechanism and may facilitate unauthorized access to the repository.","cveId":"CVE-2026-104805","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Amber","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-22","CWE-73","CWE-345","CWE-434","CWE-494"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://digitalcanion.com/en/security-research/#vendor=mitel&status=cna","type":"advisory","title":"vulnerability@ncsc.ch"}],"epssScore":0.00216,"epssPercentile":0.11029,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T09:17:09.380Z","addedAt":"2026-10-05T09:50:40.871Z","updatedAt":"2026-10-06T15:50:57.422Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104805","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104805","note":"authoritative record"}]},{"id":"e8a0dd96-21cb-4fdc-944b-93e633ad0569","slug":"cve-2026-105163","externalId":"CVE-2026-105163","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105163 — A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2.","description":"A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and 2.4.0-rc.1 is able to resolve this issue. The patch is identified as bee99c6cd6ca81878acca2940a2f0a02169fc208. You should upgrade the affected component.","cveId":"CVE-2026-105163","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"Go","product":"github.com/crossplane/crossplane-runtime/v2","affectedVersions":["pkg:golang/github.com/crossplane/crossplane-runtime/v2 >= 2.4.0-rc.0, < 2.4.0-rc.1","pkg:golang/github.com/crossplane/crossplane-runtime/v2 >= 2.3.0, < 2.3.3","pkg:golang/github.com/crossplane/crossplane-runtime/v2 >= 2.3.0, < 2.3.3 || >= 2.4.0-rc.0, < 2.4.0-rc.1"],"cwes":["CWE-362","CWE-367","CWE-345"],"tags":["nvd","status:received","osv","osv:ghsa-mf7q-r4rv-jv94","ecosystem:go","osv:go-2026-6302","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/crossplane/crossplane-runtime/pull/1038","https://github.com/crossplane/crossplane-runtime/commit/bee99c6cd6ca81878acca2940a2f0a02169fc208"],"references":[{"url":"https://github.com/advisories/GHSA-mf7q-r4rv-jv94","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/crossplane/crossplane-runtime/","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/crossplane/crossplane-runtime/commit/bee99c6cd6ca81878acca2940a2f0a02169fc208","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/crossplane/crossplane-runtime/pull/1038","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/crossplane/crossplane-runtime/releases/tag/v2.2.3","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-105163","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413395","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413395/cti","type":"advisory","title":"cna@vuldb.com"},{"url":"https://osv.dev/vulnerability/GHSA-mf7q-r4rv-jv94","type":"advisory","title":"OSV GHSA-mf7q-r4rv-jv94"},{"url":"https://github.com/crossplane/crossplane-runtime/security/advisories/GHSA-mf7q-r4rv-jv94","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/crossplane/crossplane-runtime","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/GO-2026-6302","type":"advisory","title":"OSV GO-2026-6302"},{"url":"https://github.com/crossplane/crossplane-runtime/releases/tag/v2.3.3","type":"other","title":"OSV web"}],"epssScore":0.00322,"epssPercentile":0.2323,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-04T22:16:58.763Z","addedAt":"2026-10-04T23:50:40.031Z","updatedAt":"2026-10-06T15:50:56.716Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105163","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105163","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-MF7Q-R4RV-JV94"}]},{"id":"9ba70c34-4339-4124-bc65-6c3aab031326","slug":"cve-2026-105161","externalId":"CVE-2026-105161","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105161 — A flaw has been found in invariant-systems-ai aiir up to 1.7.0.","description":"A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected component. The GitHub repository of this project is not available anymore. This vulnerability only affects products that are no longer supported by the maintainer.","cveId":"CVE-2026-105161","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345","CWE-347"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/advisories/GHSA-73p9-6hrp-8qhr","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/invariant-systems-ai/aiir/","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/invariant-systems-ai/aiir/security/advisories/GHSA-73p9-6hrp-8qhr","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-105161","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413387","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413387/cti","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00143,"epssPercentile":0.03146,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-04T18:16:33.560Z","addedAt":"2026-10-04T19:50:39.931Z","updatedAt":"2026-10-07T00:39:29.050Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105161","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105161","note":"authoritative record"}]},{"id":"8093d120-70dd-45c8-ad00-da3159d7c801","slug":"cve-2026-85515","externalId":"CVE-2026-85515","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85515 — In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path w…","description":"In Bouncy Castle for Java before 1.86, a truncated OpenPGP encrypted message was accepted with no error reported, and on the SEIPD version 1 path with no integrity check performed at all. RFC 9580 sec. 13.7 permits an implementation to release the cleartext of the fully authenticated chunks when streaming but requires it to indicate a clear error as soon as the truncation is detected, and to report suspect integrity when it discovers malleable ciphertext. The truncation was detected and then discarded: when a message is truncated but the length field of the enclosing packet is left unchanged, BCPGInputStream.PartialInputStream raises an EOFException for the missing ciphertext, and BCPGInputStream.nextPacketTag() reports an EOFException as a clean end of message, so the packet stream above it stopped as though no packets remained. On the AEAD path (SEIPD version 2 and the version 5 AEAD packet), when the literal data packet ended on an AEAD chunk boundary and the consumer read in increments smaller than one chunk, the look-ahead for the packet after the literal triggered the truncated chunk read, so BcAEADUtil and JceAEADUtil never reached the trailing message tag of sec. 5.13.2 that authenticates the total plaintext length; the caller received the plaintext of the fully authenticated chunks, every packet following the literal was silently dropped, and no exception was raised, so a signed and encrypted message read back as a well-formed unsigned one. Every byte released on that path remained individually authenticated, making this a missing truncation error rather than a forgery, and it is a residual of CVE-2026-12817, which closed the same outcome for an attacker who corrects the outer packet length. On the SEIPD version 1 path the consequence was more serious: IntegrityProtectedInputStream verifies the modification detection code from close(), and reached close() only by closing itself when a read of it returned -1, which a truncated message never produces, so PGPEncryptedData.verify() never ran and the recipient was handed CFB-decrypted plaintext on which no integrity check of any kind had been performed. Measured on a message truncated into that shape, 136 distinct single-byte modifications of the ciphertext produced accepted, altered plaintext with no exception raised. Reachability is a property of the message rather than of attacker-supplied input: the AEAD shape held for 3 of 131 consecutive payload lengths measured, and the SEIPD version 1 shape for one payload length in sixteen, at a truncation offset that did not move with the payload length. The low-level API is unaffected, a caller that invokes PGPEncryptedData.verify() directly getting the check regardless, as are consumers reading in increments of a whole AEAD chunk or more. The AEAD decryption streams now re-throw such an EOFException as a plain IOException, which nextPacketTag() does not launder; OpenPGPMessageInputStream.close() now closes its layer's integrity-protected stream itself rather than relying on that stream having seen the end of its data; and IntegrityProtectedInputStream.close() was made idempotent, as java.io.Closeable requires, which that depends on, since the stream is genuinely closed twice on the ordinary path and PGPEncryptedData.verify() consumes the digest state behind it and cannot be run a second time. This issue also affects Bouncy Castle for Java LTS before 2.73.13, on the AEAD route only, as that edition does not ship the high-level OpenPGP API the SEIPDv1 route runs through. It also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.14 (1.0.X series), 2.0.14.1 (2.0.X series) and 2.1.14 (2.1.X series), on the AEAD route only, as those editions do not ship the high-level OpenPGP API.","cveId":"CVE-2026-85515","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345","CWE-354"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/bcgit/bc-java/commit/ab7a235d1c20e3da28ce77167a96b5c14025efa7","type":"advisory","title":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9085515","type":"advisory","title":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epssScore":0.00157,"epssPercentile":0.04221,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-03T09:17:06.073Z","addedAt":"2026-10-03T09:50:39.632Z","updatedAt":"2026-10-06T15:50:56.409Z","epssUpdatedAt":"2026-10-07T12:00:27.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85515","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85515","note":"authoritative record"}]},{"id":"d451de05-217f-44bd-bd8d-5d0495a2956b","slug":"cve-2026-71887","externalId":"CVE-2026-71887","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-71887 — In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature…","description":"In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification) signature, in the case where that binding omits a Key Flags subpacket. RFC 9580 sec. 5.2.1.8 and sec. 10.1.3 require the embedded Primary Key Binding signature on any subkey that can issue signatures; it is the subkey's own statement that it belongs to the primary key it is bound under. OpenPGPCertificate resolved the subkey's key flags two different ways. isSigningKey() goes through getKeyFlags() and getApplyingSubpacket(), which falls back to the primary key's direct-key or primary User ID self-signature when the binding signature omits the subpacket, so the subkey inherited the primary's SIGN_DATA and counted as signing-capable; verifyEmbeddedPrimaryKeyBinding(), which enforces the requirement, reads the binding signature's own hashed subpackets, found no SIGN_DATA there, and returned early as a non-signing key without ever demanding the back signature. The same subkey was therefore signing-capable - so its signatures were attributed to the certificate and OpenPGPSignature.OpenPGPDocumentSignature.isValid() returned true - while being exempt from cross-certification, where GnuPG refuses the identical certificate and message. An attacker needs only the victim's public signing subkey, which is public material: they bind it to their own primary key with a Subkey Binding signature they are able to make, carrying no Key Flags and no embedded Primary Key Binding signature, which they cannot make without the subkey's private key, and a relying party verifying one of the victim's genuinely signed messages against that certificate is told the signature is valid and given the attacker's certificate as its issuer. Because a certificate's User IDs are self-asserted, a verifier that pins on the subkey's fingerprint or key ID while taking the identity from the enclosing certificate reports a real signature under an attacker-chosen identity. This is misattribution of a genuine signature rather than forgery of a new one: no private key is recovered, and the signature must be one the grafted subkey actually made. The low-level PGPSignature / PGPPublicKeyRing API performs no binding checks by design and is unaffected. Key Flags are a statement about the key the carrying signature refers to (RFC 9580 sec. 5.2.3.29), so a subkey no longer inherits them from the certificate-wide signatures of the primary key: a Subkey Binding signature that omits the subpacket now leaves the subkey with no capabilities rather than the primary's, which makes the flags the cross-certification check consults the same flags every other decision consults. Preferences and the other subpackets a direct-key signature carries are inherited as before, and the primary key itself, whose flags legitimately come from its own direct-key or User ID self-signature, is unaffected.","cveId":"CVE-2026-71887","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345","CWE-347"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/bcgit/bc-java/commit/b51452fa48ccb578fc16b8222fce9eedf92c94d6","type":"advisory","title":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071887","type":"advisory","title":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epssScore":0.0009,"epssPercentile":0.00419,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-03T09:17:05.067Z","addedAt":"2026-10-03T09:50:39.587Z","updatedAt":"2026-10-06T15:50:56.368Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71887","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-71887","note":"authoritative record"}]},{"id":"17a3c8d6-22e2-4ccc-8b1f-9a1de7ba6c3f","slug":"cve-2026-104422","externalId":"CVE-2026-104422","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104422 — The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that ap…","description":"The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the requested hash, delaying the node's discovery of the newest block.","cveId":"CVE-2026-104422","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-g95h-hw6g-pvgv","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/zebra-before-6.3.0-block-sync-denial-of-service-via-coinbase-scriptsig-rewrite","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00178,"epssPercentile":0.06755,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:12.283Z","addedAt":"2026-10-02T13:50:40.443Z","updatedAt":"2026-10-02T19:50:41.261Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104422","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104422","note":"authoritative record"}]},{"id":"98d6b494-b78b-4c4c-9c9d-d90077cf408e","slug":"cve-2026-104419","externalId":"CVE-2026-104419","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104419 — Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the b…","description":"Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.","cveId":"CVE-2026-104419","cvssScore":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-qhr3-cvch-5fh2","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/zebra-before-6.3.0-honest-peer-banning-via-far-ahead-findblocks-hashes","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00126,"epssPercentile":0.02016,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:11.850Z","addedAt":"2026-10-02T13:50:40.428Z","updatedAt":"2026-10-05T17:50:42.204Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104419","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104419","note":"authoritative record"}]},{"id":"e4f7cc31-b077-4d32-ac3b-496e7651c8d6","slug":"cve-2026-103878","externalId":"CVE-2026-103878","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103878 — Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API.","description":"Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API.\n\n\n\nA StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed.\n\n\n\nThis issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9.\n\n\n\nUsers are recommended to upgrade to version 2.1.9, which fixes the issue.","cveId":"CVE-2026-103878","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/d98f9w01nd3zmkwrr21y0l9kdr9jpty9","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/02/6","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00213,"epssPercentile":0.10692,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T10:17:06.570Z","addedAt":"2026-10-02T11:50:39.682Z","updatedAt":"2026-10-05T19:50:42.321Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103878","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103878","note":"authoritative record"}]},{"id":"f9df8c2d-ba7f-4a50-b095-2b0d35075ec1","slug":"cve-2026-104056","externalId":"CVE-2026-104056","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104056 — Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding.","description":"Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.","cveId":"CVE-2026-104056","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-345","CWE-346","CWE-829"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://uziii2208.github.io/post/cve-2026-104056/","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00167,"epssPercentile":0.05481,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T19:17:19.033Z","addedAt":"2026-10-01T19:50:41.143Z","updatedAt":"2026-10-05T19:50:42.258Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104056","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104056","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":268,"totalPages":14,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:55:06.010Z","durationMs":32,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-345"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}