{"success":true,"data":{"threats":[{"id":"02f6cccb-77b7-4f1c-8d5d-2978bcec127b","slug":"cve-2026-107292","externalId":"CVE-2026-107292","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107292 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.","description":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 2.30.0, the Agent.to_web() and clai web development chat server does not validate the Host header, allowing a website visited by a developer to use DNS rebinding to reach a loopback-hosted agent as a same-origin service. The hostile page can read the served UI and submit chat requests that execute agent tools with the local process's privileges and credentials, causing data disclosure or unwanted side effects. Binding to localhost, Origin checks, and CSRF tokens do not prevent the same-origin DNS rebinding path. This issue is fixed in versions 1.107.5 and 2.30.0.","cveId":"CVE-2026-107292","cvssScore":6.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L","severity":"medium","vendor":"PyPI","product":"pydantic-ai","affectedVersions":["pkg:pypi/pydantic-ai >= 1.34.0, < 1.107.5","pkg:pypi/pydantic-ai >= 2.0.0b1, < 2.30.0","pkg:pypi/pydantic-ai-slim >= 1.34.0, < 1.107.5","pkg:pypi/pydantic-ai-slim >= 2.0.0b1, < 2.30.0"],"cwes":["CWE-346","CWE-350"],"tags":["nvd","status:received","osv","osv:ghsa-q2xc-rrxj-58x9","ecosystem:pypi","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/394cc1d31656620704a703a2daed752afa5135fe","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/871c7aeec5dfed2138655ccbccbf15c6d763bae7","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/7437","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/7438","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.5","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.30.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-q2xc-rrxj-58x9","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-q2xc-rrxj-58x9","type":"advisory","title":"OSV GHSA-q2xc-rrxj-58x9"},{"url":"https://github.com/pydantic/pydantic-ai","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:14.770Z","addedAt":"2026-10-08T18:39:31.693Z","updatedAt":"2026-10-08T21:05:51.105Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107292","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107292","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-Q2XC-RRXJ-58X9"}]},{"id":"b5d428db-e4c4-4a6f-b41b-d77acec04829","slug":"cve-2026-97875","externalId":"CVE-2026-97875","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97875 — Rojo's \"rojo serve\" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding.","description":"Rojo's \"rojo serve\" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all project source, write malicious code to files on disk, and launch local programs via opener::open() with no user interaction beyond visiting the page.","cveId":"CVE-2026-97875","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","severity":"high","vendor":"crates.io","product":"rojo","affectedVersions":["pkg:cargo/rojo >= 0.0.0-0, < 7.7.0"],"cwes":["CWE-350"],"tags":["nvd","status:received","osv","osv:rustsec-2026-0279","ecosystem:crates.io","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/rojo-rbx/rojo/pull/1270","type":"advisory","title":"74b3a70d-cca6-4d34-9789-e83b222ae3be"},{"url":"https://osv.dev/vulnerability/RUSTSEC-2026-0279","type":"advisory","title":"74b3a70d-cca6-4d34-9789-e83b222ae3be"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0279.html","type":"advisory","title":"74b3a70d-cca6-4d34-9789-e83b222ae3be"},{"url":"https://crates.io/crates/rojo","type":"vendor","title":"OSV package"},{"url":"https://github.com/rojo-rbx/rojo/commit/ac6941f05483b0875fda52c7664cd42033db7fa2","type":"other","title":"OSV web"}],"epssScore":0.0026,"epssPercentile":0.16227,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-25T11:17:16.470Z","addedAt":"2026-09-25T11:50:38.646Z","updatedAt":"2026-09-30T17:50:45.017Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97875","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97875","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/RUSTSEC-2026-0279"}]},{"id":"a252fdb1-efe7-4f49-9f8a-121901981cd7","slug":"cve-2026-61743","externalId":"CVE-2026-61743","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-61743 — Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts.","description":"Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's server/modules/safeRequest.js calls validateOutboundUrl() to resolve and validate a target hostname, but request-promise performs a separate DNS resolution for the actual connection. An authenticated user who can create or test API connections and controls the target DNS name can return a public address during validation and a private address during the request, bypassing the protections implemented by server/modules/outboundTargetPolicy.js. This DNS rebinding condition can expose internal services, localhost resources, or cloud metadata endpoints. This issue is fixed in version 5.2.2.","cveId":"CVE-2026-61743","cvssScore":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-350"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/chartbrew/chartbrew/commit/d38d745fe9e45563be8c33e4c7a17788ee6f13a3","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/chartbrew/chartbrew/releases/tag/v5.2.2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/chartbrew/chartbrew/security/advisories/GHSA-9537-vm84-j26f","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00405,"epssPercentile":0.32719,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-21T22:16:57.823Z","addedAt":"2026-09-21T23:50:36.619Z","updatedAt":"2026-09-24T21:50:43.524Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61743","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61743","note":"authoritative record"}]},{"id":"cee57199-2793-42d7-b7f3-4c5c0db34623","slug":"cve-2026-61568","externalId":"CVE-2026-61568","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-61568 — `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab.","description":"`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host` and `Origin`. The server accepts those headers and reaches the MCP initialization path instead of rejecting the request at the HTTP boundary. Version 2.1.30 contains a patch.","cveId":"CVE-2026-61568","cvssScore":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"critical","vendor":"npm","product":"@zereight/mcp-gitlab","affectedVersions":["pkg:npm/%40zereight/mcp-gitlab < 2.1.30"],"cwes":["CWE-350"],"tags":["nvd","status:received","osv","osv:ghsa-vmp7-252j-cwp7","ecosystem:npm","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/zereight/gitlab-mcp/commit/52207c6f5c0e7a39e9235d491225edbb562a0290","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/zereight/gitlab-mcp/pull/555","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/zereight/gitlab-mcp/releases/tag/v2.1.30","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/zereight/gitlab-mcp/security/advisories/GHSA-vmp7-252j-cwp7","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-vmp7-252j-cwp7","type":"advisory","title":"OSV GHSA-vmp7-252j-cwp7"},{"url":"https://github.com/zereight/gitlab-mcp","type":"vendor","title":"OSV package"}],"epssScore":0.00532,"epssPercentile":0.43178,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-15T21:16:41.570Z","addedAt":"2026-09-15T21:50:40.113Z","updatedAt":"2026-09-30T19:50:41.743Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61568","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61568","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-VMP7-252J-CWP7"}]},{"id":"f7683fd0-023f-4b9e-9713-e08b9b0b4570","slug":"cve-2026-53708","externalId":"CVE-2026-53708","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-53708 — ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC A…","description":"ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls validate_gateway_test_url() in mcpgateway/common/validators.py to resolve and reject private, loopback, link-local, and cloud-metadata addresses, but ResilientHttpClient later resolves the original hostname again without binding the validated address. When MCPGATEWAY_ADMIN_API_ENABLED is enabled, an attacker with a database-backed role containing explicit gateways.read permission can use DNS rebinding to return a public address during validation and a private or metadata address during connection, bypassing ssrf_blocked_networks and ssrf_dns_fail_closed because those controls apply only to the validation-time result. The endpoint's allow_admin_bypass=False setting means a bootstrap-only virtual platform-admin identity without a database role is not sufficient. Successful exploitation can reach internal services and cloud metadata, expose cloud credentials, access internal APIs, or probe internal network ports. This issue is fixed in version 1.0.3.","cveId":"CVE-2026-53708","cvssScore":6.6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N","severity":"medium","vendor":"PyPI","product":"mcp-contextforge-gateway","affectedVersions":["pkg:pypi/mcp-contextforge-gateway < 1.0.3"],"cwes":["CWE-350","CWE-367","CWE-918"],"tags":["osv","osv:ghsa-9hgc-g3w5-67cm","ecosystem:pypi","osv:pysec-2026-3684","nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-9hgc-g3w5-67cm","type":"advisory","title":"OSV GHSA-9hgc-g3w5-67cm"},{"url":"https://github.com/IBM/mcp-context-forge/security/advisories/GHSA-9hgc-g3w5-67cm","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/IBM/mcp-context-forge","type":"vendor","title":"OSV package"},{"url":"https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.3","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-3684","type":"advisory","title":"OSV PYSEC-2026-3684"},{"url":"https://pypi.org/project/mcp-contextforge-gateway","type":"vendor","title":"OSV package"},{"url":"https://github.com/advisories/GHSA-9hgc-g3w5-67cm","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53708","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/IBM/mcp-context-forge/commit/fba11a99babd80779fa05510b35fb6a153bbacaf","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.0035,"epssPercentile":0.26556,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-14T16:17:11.883Z","addedAt":"2026-08-15T01:54:33.819Z","updatedAt":"2026-09-30T21:50:42.518Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53708","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-53708","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-9HGC-G3W5-67CM"}]},{"id":"250adec7-8c7f-4da6-b5f4-c080373317e4","slug":"cve-2026-57123","externalId":"CVE-2026-57123","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-57123 — PraisonAI is a multi-agent teams system.","description":"PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authentication, origin-validation, or DNS-rebinding controls. Any reachable client can list and invoke registered tools, and a browser can target a local instance through DNS rebinding, with impact determined by the registered file, shell, and code-execution tools. This vulnerability is fixed in praisonaiagents 1.6.59.","cveId":"CVE-2026-57123","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"PyPI","product":"praisonaiagents","affectedVersions":["pkg:pypi/praisonaiagents < 1.6.59"],"cwes":["CWE-1327","CWE-306","CWE-350"],"tags":["osv","osv:ghsa-x227-pf99-vffg","ecosystem:pypi","osv:pysec-2026-3536","nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-x227-pf99-vffg","type":"advisory","title":"OSV GHSA-x227-pf99-vffg"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-x227-pf99-vffg","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-3536","type":"advisory","title":"OSV PYSEC-2026-3536"},{"url":"https://pypi.org/project/praisonaiagents","type":"vendor","title":"OSV package"},{"url":"https://github.com/advisories/GHSA-x227-pf99-vffg","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57123","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/2adfe7e8323f6deec66925cf15a885b6238895e9","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.59","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00904,"epssPercentile":0.58576,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-14T15:17:05.753Z","addedAt":"2026-07-29T20:52:09.654Z","updatedAt":"2026-09-15T15:50:36.982Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57123","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-57123","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-X227-PF99-VFFG"}]},{"id":"8ee817ff-ac17-4cc3-a432-b0d30c1f7074","slug":"cve-2026-55526","externalId":"CVE-2026-55526","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-55526 — PraisonAI is a multi-agent teams system.","description":"PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resolve ordinary hostnames before scrape_page fetches them. A hostname such as 127.0.0.1.nip.io passes validation and resolves to loopback, permitting internal HTTP access. The fix uses socket.getaddrinfo and fails closed on DNS errors. This issue is fixed in version 1.6.58.","cveId":"CVE-2026-55526","cvssScore":8.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","severity":"high","vendor":"PyPI","product":"praisonaiagents","affectedVersions":["pkg:pypi/praisonaiagents < 1.6.58"],"cwes":["CWE-350","CWE-918"],"tags":["nvd","status:received","osv","osv:ghsa-x44h-65qv-cw74","ecosystem:pypi","status:deferred","osv:pysec-2026-3905"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/MervinPraison/PraisonAI/commit/2f9677abb2ea68eab864ee8b6a828fd0141612e1","type":"other","title":"OSV web"},{"url":"https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.58","type":"other","title":"OSV web"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-x44h-65qv-cw74","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-x44h-65qv-cw74","type":"advisory","title":"OSV GHSA-x44h-65qv-cw74"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-3905","type":"advisory","title":"OSV PYSEC-2026-3905"},{"url":"https://pypi.org/project/praisonaiagents","type":"vendor","title":"OSV package"},{"url":"https://github.com/advisories/GHSA-x44h-65qv-cw74","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55526","type":"advisory","title":"OSV advisory"}],"epssScore":0.00357,"epssPercentile":0.27348,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-25T15:16:33.300Z","addedAt":"2026-08-25T15:50:33.464Z","updatedAt":"2026-09-10T13:54:37.112Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55526","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-55526","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-X44H-65QV-CW74"}]},{"id":"6b268402-361e-462e-8430-cb8d51f0d7ca","slug":"cve-2026-56709","externalId":"CVE-2026-56709","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-56709 — Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links.","description":"Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows.","cveId":"CVE-2026-56709","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-350"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/getgrav/grav/security/advisories/GHSA-69vf-mjxw-x79j","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/grav-before-host-header-injection-via-sendinvitationemail","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00434,"epssPercentile":0.35704,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-25T02:16:42.930Z","addedAt":"2026-08-25T03:50:29.742Z","updatedAt":"2026-08-31T21:50:32.824Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56709","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-56709","note":"authoritative record"}]},{"id":"643eeee8-8bb7-49ba-ac31-059de8b1bc5d","slug":"cve-2026-75514","externalId":"CVE-2026-75514","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-75514 — BunkerWeb is an open-source, next-generation Web Application Firewall.","description":"BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot modules in src/common/core/blacklist/blacklist.lua, src/common/core/greylist/greylist.lua, and src/common/core/antibot/antibot.lua trust PTR suffix matches in IGNORE_RDNS, GREYLIST_RDNS, and ANTIBOT_IGNORE_RDNS without using get_ips to confirm that the hostname resolves to the client address. An unauthenticated remote attacker who controls a PTR record can spoof a trusted suffix to bypass rDNS-based blacklisting, gain greylist treatment, or skip an antibot challenge. This issue is fixed in version 1.6.13.","cveId":"CVE-2026-75514","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-350"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/bunkerity/bunkerweb/commit/1a97e5b3f977130a1b84507a9e1f703c8eec12eb","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/bunkerity/bunkerweb/pull/3710","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/bunkerity/bunkerweb/releases/tag/v1.6.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/bunkerity/bunkerweb/security/advisories/GHSA-q54j-5484-pvjm","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00597,"epssPercentile":0.46927,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-20T19:17:03.637Z","addedAt":"2026-08-20T19:50:29.226Z","updatedAt":"2026-09-18T21:50:37.355Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75514","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-75514","note":"authoritative record"}]},{"id":"81ce7d4f-f936-49a1-9165-a0516b1a643c","slug":"cve-2026-63118","externalId":"CVE-2026-63118","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-63118 — MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients.","description":"MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not validate the HTTP Host or Origin request headers, which allows a malicious browser page to use DNS rebinding to reach a locally running MCP server and invoke exposed tools. This issue is fixed in version 0.23.0.","cveId":"CVE-2026-63118","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"RubyGems","product":"mcp","affectedVersions":["pkg:gem/mcp < 0.23.0"],"cwes":["CWE-346","CWE-350"],"tags":["nvd","status:received","osv","osv:ghsa-rjr6-rcgv-9m7m","ecosystem:rubygems","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/modelcontextprotocol/ruby-sdk/commit/ba543083a7594e7892b29464b89091816446ff7a","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-rjr6-rcgv-9m7m","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-rjr6-rcgv-9m7m","type":"advisory","title":"OSV GHSA-rjr6-rcgv-9m7m"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63118","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/modelcontextprotocol/ruby-sdk","type":"vendor","title":"OSV package"}],"epssScore":0.00256,"epssPercentile":0.15806,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-29T20:17:10.630Z","addedAt":"2026-07-29T20:17:40.664Z","updatedAt":"2026-07-30T21:34:50.456Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63118","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-63118","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-RJR6-RCGV-9M7M"}]},{"id":"4b301108-5d01-4ba2-bdd3-3e0d8be544fe","slug":"cve-2026-55391","externalId":"CVE-2026-55391","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-55391 — datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobu…","description":"datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.63.0, datamodel-code-generator validates a URL host once in src/datamodel_code_generator/http.py through get_body, _validate_url_for_fetch, and _get_ips_from_host, but then lets httpx resolve the host again for the connection, allowing DNS rebinding to bypass allow_private_network=False and reach internal services. This issue is fixed in version 0.63.0.","cveId":"CVE-2026-55391","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N","severity":"high","vendor":"koxudaxi","product":"datamodel-code-generator","affectedVersions":["pkg:pypi/datamodel-code-generator < 0.63.0","< 0.63.0"],"cwes":["CWE-350","CWE-367","CWE-918"],"tags":["nvd","status:received","osv","osv:ghsa-vx7x-vcc2-c44g","ecosystem:pypi","status:awaiting-analysis","osv:pysec-2026-3565","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/koxudaxi/datamodel-code-generator/commit/25c8b7e497419eb20b230fa3318c04f9bebc5a6f"],"references":[{"url":"https://github.com/koxudaxi/datamodel-code-generator/commit/25c8b7e497419eb20b230fa3318c04f9bebc5a6f","type":"patch","title":"Patch"},{"url":"https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.63.0","type":"advisory","title":"Release Notes"},{"url":"https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-vx7x-vcc2-c44g","type":"vendor","title":"Exploit"},{"url":"https://gist.github.com/thegr1ffyn/c1d54dd6ff2a4c0d7d0dabe00c4985f4","type":"advisory","title":"Third Party Advisory"},{"url":"https://osv.dev/vulnerability/GHSA-vx7x-vcc2-c44g","type":"advisory","title":"OSV GHSA-vx7x-vcc2-c44g"},{"url":"https://github.com/koxudaxi/datamodel-code-generator","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-3565","type":"advisory","title":"OSV PYSEC-2026-3565"},{"url":"https://pypi.org/project/datamodel-code-generator","type":"vendor","title":"OSV package"},{"url":"https://github.com/advisories/GHSA-vx7x-vcc2-c44g","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55391","type":"advisory","title":"OSV advisory"}],"epssScore":0.00305,"epssPercentile":0.21335,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-28T22:17:48.697Z","addedAt":"2026-07-28T22:18:16.853Z","updatedAt":"2026-08-06T19:50:23.888Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55391","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-55391","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-VX7X-VCC2-C44G"}]},{"id":"f2ab75bb-eb52-44a2-a961-e519ec121bcf","slug":"cve-2026-36604","externalId":"CVE-2026-36604","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-36604 — Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS rebinding attacks.","description":"Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS rebinding attacks. An external attacker can rebind a domain to the router's internal IP address, extending the CORS wildcard vulnerability (Access-Control-Allow-Origin: *) to internet-originated attacks.","cveId":"CVE-2026-36604","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-350"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Tymbark7372/MERCUSYS-AC12G/blob/master/advisories/CVE-2026-36604.md","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00354,"epssPercentile":0.27099,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-06-03T18:16:21.420Z","addedAt":"2026-07-28T20:12:14.881Z","updatedAt":"2026-07-28T20:12:14.881Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-36604","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-36604","note":"authoritative record"}]},{"id":"82fdef70-3014-4b12-8aec-1f17875b0490","slug":"cve-2026-43582","externalId":"GHSA-xq94-r468-qwgj","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding","description":"## Summary\n\nBrowser SSRF hostname validation could be bypassed by DNS rebinding.\n\n## Affected Packages / Versions\n\n- Package: `openclaw`\n- Ecosystem: npm\n- Affected versions: `< 2026.4.10`\n- Patched versions: `>= 2026.4.10`\n\n## Impact\n\nBrowser navigation policy could validate a hostname/IP resolution that differed from the address Chromium ultimately used, allowing DNS rebinding style SSRF pivots.\n\n## Technical Details\n\nThe fix tightens strict browser hostname navigation so unallowlisted hostname URLs fail closed under restrictive policy.\n\n## Fix\n\nThe issue was fixed in #64367. The first stable tag containing the fix is `v2026.4.10`, and `openclaw@2026.4.14` includes the fix.\n\n## Fix Commit(s)\n\n- `121c452d666d4749744dc2089287d0227aae2ed3`\n- PR: #64367\n\n## Release Process Note\n\nUsers should upgrade to `openclaw` 2026.4.10 or newer. The latest npm release, `2026.4.14`, already includes the fix.\n\n## Credits\n\nThanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.","cveId":"CVE-2026-43582","cvssScore":null,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","severity":"medium","vendor":"npm","product":"openclaw","affectedVersions":["pkg:npm/openclaw < 2026.4.10"],"cwes":["CWE-350","CWE-918"],"tags":["osv","osv:ghsa-xq94-r468-qwgj","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-xq94-r468-qwgj","type":"advisory","title":"OSV GHSA-xq94-r468-qwgj"},{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-xq94-r468-qwgj","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43582","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/openclaw/openclaw/pull/64367","type":"other","title":"OSV web"},{"url":"https://github.com/openclaw/openclaw/commit/121c452d666d4749744dc2089287d0227aae2ed3","type":"other","title":"OSV web"},{"url":"https://github.com/openclaw/openclaw","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/openclaw-dns-rebinding-ssrf-via-hostname-validation-bypass","type":"other","title":"OSV web"}],"epssScore":0.00308,"epssPercentile":0.2168,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-04-17T21:58:01.000Z","addedAt":"2026-09-10T07:55:09.225Z","updatedAt":"2026-09-10T07:55:09.225Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43582","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-43582","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-xq94-r468-qwgj"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-xq94-r468-qwgj"}]},{"id":"fa62eda7-4313-4e9b-8fb6-a3144e663b16","slug":"cve-2025-8036","externalId":"CVE-2025-8036","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2025-8036 — Thunderbird cached CORS preflight responses across IP address changes.","description":"Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.","cveId":"CVE-2025-8036","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","severity":"high","vendor":"mozilla","product":"firefox","affectedVersions":["< 140.1.0","< 141.0"],"cwes":["CWE-350"],"tags":["nvd","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1960834","type":"advisory","title":"Permissions Required"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-56/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-59/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-61/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.mozilla.org/security/advisories/mfsa2025-63/","type":"vendor","title":"Vendor Advisory"},{"url":"https://www.kb.cert.org/vuls/id/652514","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00424,"epssPercentile":0.34697,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2025-07-22T21:15:50.760Z","addedAt":"2026-09-30T19:50:40.155Z","updatedAt":"2026-10-05T15:50:43.632Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8036","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2025-8036","note":"authoritative record"}]},{"id":"b24ed6ae-5d21-431d-bb56-d43a99636772","slug":"cve-2018-7160","externalId":"CVE-2018-7160","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2018-7160 — The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution.","description":"The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious websites open in a web browser on the same computer, or another computer with network access to the computer running the Node.js process. A malicious website could use a DNS rebinding attack to trick the web browser to bypass same-origin-policy checks and to allow HTTP connections to localhost or to hosts on the local network. If a Node.js process with the debug port active is running on localhost or on a host on the local network, the malicious website could connect to it as a debugger, and get full code execution access.","cveId":"CVE-2018-7160","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"nodejs","product":"node.js","affectedVersions":[">= 6.0.0, <= 6.8.1",">= 6.9.0, < 6.14.0",">= 8.0.0, <= 8.8.1",">= 8.9.0, < 8.11.0",">= 9.0.0, < 9.10.0"],"cwes":["CWE-350","CWE-290"],"tags":["nvd","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/","type":"vendor","title":"Vendor Advisory"},{"url":"https://support.f5.com/csp/article/K63025104?utm_source=f5support&amp%3Butm_medium=RSS","type":"advisory","title":"cve-request@iojs.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","type":"advisory","title":"Third Party Advisory"},{"url":"https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/","type":"vendor","title":"Vendor Advisory"},{"url":"https://support.f5.com/csp/article/K63025104?utm_source=f5support&amp%3Butm_medium=RSS","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","type":"advisory","title":"Third Party Advisory"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2018-05-17T14:29:00.827Z","addedAt":"2026-10-08T23:06:21.100Z","updatedAt":"2026-10-08T23:06:21.100Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-7160","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2018-7160","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":15,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T04:01:40.300Z","durationMs":21,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-350"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}