{"success":true,"data":{"threats":[{"id":"6065f93f-cb54-406b-b139-3b1bbbb1efd5","slug":"cve-2026-96760","externalId":"CVE-2026-96760","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-96760 — Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability.","description":"Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.","cveId":"CVE-2026-96760","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-20","CWE-347","CWE-358","CWE-670"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/authlib/authlib","type":"advisory","title":"cret@cert.org"},{"url":"https://kb.cert.org/vuls/id/762428","type":"advisory","title":"cret@cert.org"},{"url":"https://www.kb.cert.org/vuls/id/762428","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00278,"epssPercentile":0.18594,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T20:17:11.703Z","addedAt":"2026-09-28T21:50:39.562Z","updatedAt":"2026-10-01T15:50:40.153Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96760","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-96760","note":"authoritative record"}]},{"id":"0ab499f4-93eb-4b3c-a80a-7489d1416093","slug":"cve-2026-46582","externalId":"CVE-2026-46582","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-46582 — In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC s…","description":"In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. When the resolving thread puts secure on the rrset, and another thread that is on the serve expired path then picks up the updated rrset contents with the secure status for a reply, it can be used to change a specific record, next to a wildcard that could be covered by the wildcard, into the wildcard. A malicious actor can exploit the possible poisonous effect by having any DNSSEC-singed domain (irrelevant to the victim domain) and a CNAME wrapper record that points to a record next to a wildcard (that could be covered by the wildcard). Then quering Unbound for the wildcard sibling record would seed the secure message. A later (after expiry) query for the CNAME wrapper would need to resolve the target sibling record. If the wildcard replay is injected into the response, the wildcard rrset will update the expired sibling record with a secure status before completing proper wildcard validation with NSEC records and eventually treating the CNAME wrapper answer as bogus. The updated poisoned rrset is now secure and points to the wildcard. This vulnerability is explicit for the serve expired path and needs injection of the signed wildcard rrset without the NSEC accompanying rrset.","cveId":"CVE-2026-46582","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"low","vendor":"nlnetlabs","product":"unbound","affectedVersions":[">= 1.6.0, < 1.25.2"],"cwes":["CWE-358"],"tags":["nvd","status:analyzed","msrc","vendor-advisory","microsoft","cve"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46582"],"references":[{"url":"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-46582.txt","type":"vendor","title":"Vendor Advisory"},{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46582","type":"vendor","title":"Microsoft MSRC: CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path"}],"epssScore":0.00189,"epssPercentile":0.07761,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-22T14:17:19.397Z","addedAt":"2026-07-28T20:12:34.277Z","updatedAt":"2026-07-29T20:52:59.884Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46582","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-46582","note":"authoritative record"}]},{"id":"6ff0c3fa-a180-4160-8ed7-81a9e780bb28","slug":"cve-2026-65058","externalId":"CVE-2026-65058","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-65058 — Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow.","description":"Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only the initial calldata chunk while the signature commits to the full streamed calldata. An attacker could present calldata to a victim then supply a different tail that changes the signed transaction. Fixed in 70c9b0c.","cveId":"CVE-2026-65058","cvssScore":5.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-358"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/trezor/trezor-firmware/commit/70c9b0c07748","type":"advisory","title":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-202-02.json","type":"advisory","title":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-65058","type":"advisory","title":"9119a7d8-5eab-497f-8521-727c672e3725"}],"epssScore":0.00398,"epssPercentile":0.31913,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-21T21:16:54.567Z","addedAt":"2026-07-28T20:12:29.553Z","updatedAt":"2026-07-30T19:34:48.182Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65058","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-65058","note":"authoritative record"}]},{"id":"c82eaab0-da0d-4dcc-ab5e-1f491461fb4a","slug":"cve-2026-49783","externalId":"CVE-2026-49783","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-49783 — Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.","description":"Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.","cveId":"CVE-2026-49783","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"microsoft","product":"windows 10 1607","affectedVersions":["< 10.0.14393.9339","< 10.0.17763.9020","< 10.0.19044.7548","< 10.0.19045.7548","< 10.0.26100.8875","< 10.0.26200.8875","< 10.0.28000.2269","< 10.0.28000.2525","< 10.0.20348.5386","< 10.0.26100.33158"],"cwes":["CWE-358"],"tags":["nvd","status:analyzed","msrc","vendor-advisory","microsoft","cve"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49783"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49783","type":"vendor","title":"Microsoft MSRC: CVE-2026-49783 Secure Boot Security Feature Bypass Vulnerability"}],"epssScore":0.00333,"epssPercentile":0.24615,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-14T17:16:53.747Z","addedAt":"2026-07-28T20:12:24.534Z","updatedAt":"2026-07-29T20:53:02.125Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49783","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-49783","note":"authoritative record"}]},{"id":"eb94256c-d249-4399-8327-88f0496dd701","slug":"cve-2026-57915","externalId":"CVE-2026-57915","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-57915 — It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type.","description":"It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.","cveId":"CVE-2026-57915","cvssScore":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-304","CWE-358"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/1y3glgh3kzwoxo5m2lq504cjlh1dsrfh","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/06/26/8","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/security/cve/CVE-2026-57915","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493407","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57915.json","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epssScore":0.00526,"epssPercentile":0.42737,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-06-26T13:16:35.740Z","addedAt":"2026-08-03T14:30:47.074Z","updatedAt":"2026-08-03T14:30:47.074Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57915","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-57915","note":"authoritative record"}]},{"id":"6f31b75d-8405-4955-99c2-fd8f997ed1b9","slug":"cve-2026-50628","externalId":"CVE-2026-50628","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-50628 — A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any oth…","description":"A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this\n\nsecurity feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.","cveId":"CVE-2026-50628","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"apache","product":"cxf","affectedVersions":["< 4.1.7",">= 4.2.0, < 4.2.2","pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2 >= 4.2.0, < 4.2.2","pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2 < 4.1.7"],"cwes":["CWE-20","CWE-358"],"tags":["nvd","status:modified","osv","osv:ghsa-g5v7-jchf-7jrr","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/vb3ho8lf228gh90m1fpnohf2008xrdxk","type":"other","title":"OSV web"},{"url":"http://www.openwall.com/lists/oss-security/2026/06/11/5","type":"other","title":"OSV web"},{"url":"https://access.redhat.com/errata/RHSA-2026:37390","type":"other","title":"OSV web"},{"url":"https://access.redhat.com/security/cve/CVE-2026-50628","type":"other","title":"OSV web"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488302","type":"other","title":"OSV web"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50628.json","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-g5v7-jchf-7jrr","type":"advisory","title":"OSV GHSA-g5v7-jchf-7jrr"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50628","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/apache/cxf","type":"vendor","title":"OSV package"}],"epssScore":0.01022,"epssPercentile":0.62386,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-06-12T10:16:22.710Z","addedAt":"2026-08-07T13:50:33.486Z","updatedAt":"2026-08-21T19:54:56.108Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50628","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-50628","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-G5V7-JCHF-7JRR"}]},{"id":"e747bc59-27c0-4977-a367-840bda64e7c6","slug":"cve-2026-11127","externalId":"CVE-2026-11127","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-11127 — Inappropriate implementation in WebAPKs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via…","description":"Inappropriate implementation in WebAPKs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted WebAPK. (Chromium security severity: Medium)","cveId":"CVE-2026-11127","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 149.0.7827.53"],"cwes":["CWE-358"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html","type":"vendor","title":"Vendor Advisory"},{"url":"https://issues.chromium.org/issues/501535295","type":"advisory","title":"Permissions Required"}],"epssScore":0.00168,"epssPercentile":0.05623,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-06-04T23:17:18.707Z","addedAt":"2026-07-28T20:12:16.895Z","updatedAt":"2026-07-28T20:12:16.895Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11127","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-11127","note":"authoritative record"}]},{"id":"c00bc978-22ee-4220-b72b-202364d9f6be","slug":"cve-2026-11122","externalId":"CVE-2026-11122","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-11122 — Inappropriate implementation in Keyboard in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXS…","description":"Inappropriate implementation in Keyboard in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-11122","cvssScore":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 149.0.7827.53"],"cwes":["CWE-358"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html","type":"vendor","title":"Vendor Advisory"},{"url":"https://issues.chromium.org/issues/501485453","type":"advisory","title":"Permissions Required"}],"epssScore":0.00172,"epssPercentile":0.05999,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-06-04T23:17:18.023Z","addedAt":"2026-07-28T20:12:16.877Z","updatedAt":"2026-07-28T20:12:16.877Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11122","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-11122","note":"authoritative record"}]},{"id":"f89cf989-32a7-4b10-8fb2-eec899318487","slug":"cve-2026-40597","externalId":"CVE-2026-40597","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-40597 — Mantis Bug Tracker (MantisBT) is an open source issue tracker.","description":"Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerability, an attacker can bypass the Content Security Policy's script-src directive by uploading a crafted attachment to any issue that, when accessed via the file_download.php link, will be downloaded with a valid JavaScript MIME type resulting in script execution. The uploaded payload must be sniffed as a valid JavaScript MIME type by PHP finfo (see file_create_finfo() API function). Non-JavaScript MIME types will not get imported in a <script> tag by the browser, due to response header X-Content-Type-Options being set to nosniff, which requires all imported JavaScript files to be a valid JavaScript MIME type. This issue has been fixed in version 2.28.2.","cveId":"CVE-2026-40597","cvssScore":7.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-79","CWE-358"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mantisbt/mantisbt/commit/9e3bee2e7b909f4e3596985892b8bc8bee9e0bfe","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-9c3j-xm6v-j7j3","type":"advisory","title":"security-advisories@github.com"},{"url":"https://mantisbt.org/bugs/view.php?id=37016","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00587,"epssPercentile":0.46372,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-05-22T20:16:34.347Z","addedAt":"2026-07-28T20:12:09.018Z","updatedAt":"2026-07-28T20:12:09.018Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40597","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-40597","note":"authoritative record"}]},{"id":"e400ce2d-e160-42c9-a54b-c4c046859667","slug":"cve-2026-44513","externalId":"CVE-2026-44513","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-44513 — Diffusers is the a library for  pretrained diffusion models.","description":"Diffusers is the a library for  pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulnerability has three variants, all sharing the same root cause — the trust_remote_code gate was implemented inside DiffusionPipeline.download() rather than at the actual dynamic-module load site, so any code path that bypassed or short-circuited download() also bypassed the security check. DiffusionPipeline.from_pretrained('repoA', custom_pipeline='attacker/repoB', trust_remote_code=False) — the gate evaluated against repoA's file list rather than repoB's, so repoB's pipeline.py was loaded and executed. DiffusionPipeline.from_pretrained('/local/snapshot', custom_pipeline='attacker/repoB', trust_remote_code=False) — the local-path branch never invoked download(), so the gate was never reached and remote code from repoB executed. DiffusionPipeline.from_pretrained('/local/snapshot', trust_remote_code=False) where the snapshot contains custom component files (e.g. unet/my_unet_model.py) referenced from model_index.json — same root cause; the local path skipped download() and custom component code executed. This vulnerability is fixed in 0.38.0.","cveId":"CVE-2026-44513","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"huggingface","product":"diffusers","affectedVersions":["< 0.38.0"],"cwes":["CWE-94","CWE-358"],"tags":["nvd","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/huggingface/diffusers/security/advisories/GHSA-98h9-4798-4q5v","type":"vendor","title":"Exploit"},{"url":"https://access.redhat.com/errata/RHSA-2026:60520","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-44513","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477507","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44513.json","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epssScore":0.0089,"epssPercentile":0.58133,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-05-14T17:16:22.903Z","addedAt":"2026-08-28T17:50:32.815Z","updatedAt":"2026-08-28T17:50:32.815Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44513","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-44513","note":"authoritative record"}]},{"id":"d36ff977-81a4-4e30-9b11-c3206bdf47c8","slug":"cve-2026-45109","externalId":"CVE-2026-45109","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-45109 — Next.js is a React framework for building full-stack web applications.","description":"Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.","cveId":"CVE-2026-45109","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":"vercel","product":"next.js","affectedVersions":[">= 15.2.0, < 15.5.18",">= 16.0.0, < 16.2.6"],"cwes":["CWE-288","CWE-358"],"tags":["nvd","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/vercel/next.js/security/advisories/GHSA-26hh-7cqf-hhc6","type":"vendor","title":"Vendor Advisory"},{"url":"https://access.redhat.com/errata/RHSA-2026:34608","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:37272","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:40974","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:54435","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-45109","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477190","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45109.json","type":"advisory","title":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epssScore":0.00761,"epssPercentile":0.53942,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-05-13T18:16:19.283Z","addedAt":"2026-08-13T13:50:44.967Z","updatedAt":"2026-08-13T13:50:44.967Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45109","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-45109","note":"authoritative record"}]},{"id":"dca29ca5-a72b-4904-9578-99ec27611343","slug":"cve-2026-28914","externalId":"CVE-2026-28914","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-28914 — A logic issue was addressed with improved file handling.","description":"A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.","cveId":"CVE-2026-28914","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","severity":"medium","vendor":"apple","product":"macos","affectedVersions":[">= 26.0, < 26.5"],"cwes":["CWE-358","CWE-693"],"tags":["nvd","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.apple.com/en-us/127115","type":"vendor","title":"Release Notes"},{"url":"https://support.apple.com/en-us/128071","type":"advisory","title":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/128072","type":"advisory","title":"product-security@apple.com"}],"epssScore":0.00172,"epssPercentile":0.06039,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-05-11T21:18:53.903Z","addedAt":"2026-07-28T20:12:06.107Z","updatedAt":"2026-07-28T20:12:06.107Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28914","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-28914","note":"authoritative record"}]},{"id":"f394b91c-eff2-4f1f-854d-f34951d259b8","slug":"cve-2025-31983","externalId":"CVE-2025-31983","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2025-31983 — HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header.","description":"HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header.  This could allow attackers to inject malicious scripts increasing the risk of cross-site scripting (XSS) and potential exposure of sensitive information.","cveId":"CVE-2025-31983","cvssScore":4.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","severity":"medium","vendor":"hcltech","product":"bigfix service management","affectedVersions":["23.0"],"cwes":["CWE-358"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0128144","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00118,"epssPercentile":0.01594,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-05-06T15:16:07.783Z","addedAt":"2026-09-30T23:50:46.562Z","updatedAt":"2026-10-07T10:39:38.210Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-31983","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2025-31983","note":"authoritative record"}]},{"id":"df6af04b-3ec2-4588-b159-cc7b5816830f","slug":"cve-2025-31970","externalId":"CVE-2025-31970","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2025-31970 — HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict di…","description":"HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could allow an attacker to exploit injection vectors such as Cross-Site Scripting (XSS)","cveId":"CVE-2025-31970","cvssScore":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","severity":"medium","vendor":"hcltech","product":"dfxanalytics","affectedVersions":["< 4.1"],"cwes":["CWE-358","CWE-79"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130569","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00149,"epssPercentile":0.03551,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-05-06T11:16:03.650Z","addedAt":"2026-09-30T23:50:46.484Z","updatedAt":"2026-10-07T10:39:38.058Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-31970","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2025-31970","note":"authoritative record"}]},{"id":"4a47b19d-4ace-44ea-be0f-5d293bd9c4bd","slug":"cve-2026-5894","externalId":"CVE-2026-5894","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-5894 — Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a craft…","description":"Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)","cveId":"CVE-2026-5894","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 147.0.7727.55"],"cwes":["CWE-358"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/481882038","type":"advisory","title":"Issue Tracking"}],"epssScore":0.00242,"epssPercentile":0.14067,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-04-08T22:16:29.290Z","addedAt":"2026-07-28T20:12:03.376Z","updatedAt":"2026-07-28T20:12:03.376Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5894","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-5894","note":"authoritative record"}]},{"id":"d5d099a7-713e-4ec1-a52f-8cd546d56190","slug":"cve-2026-35679","externalId":"CVE-2026-35679","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-35679 — Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draini…","description":"Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.","cveId":"CVE-2026-35679","cvssScore":3.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-358"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/zcash/zcash/commit/db969c63f48f0f9fc518112ed0b7ace1af78b9d0","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/zcash/zcash/releases/tag/v6.12.0","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00252,"epssPercentile":0.15255,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-04-05T22:16:01.193Z","addedAt":"2026-07-28T20:12:00.401Z","updatedAt":"2026-07-28T20:12:00.401Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35679","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-35679","note":"authoritative record"}]},{"id":"6b6e43ca-8806-4e17-9a03-8c1e93ba14e6","slug":"cve-2025-69234","externalId":"CVE-2025-69234","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2025-69234 — Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.","description":"Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.","cveId":"CVE-2025-69234","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"critical","vendor":"navercorp","product":"whale","affectedVersions":["< 4.35.351.12"],"cwes":["CWE-358"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cve.naver.com/detail/cve-2025-69234.html","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00291,"epssPercentile":0.19859,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2025-12-30T02:16:16.810Z","addedAt":"2026-10-05T17:50:40.868Z","updatedAt":"2026-10-07T12:39:41.522Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69234","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2025-69234","note":"authoritative record"}]},{"id":"c6c1aaac-d1df-4ff6-ad43-beb255be2d0d","slug":"cve-2025-66323","externalId":"CVE-2025-66323","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2025-66323 — Vulnerability of improper criterion security check in the card module.","description":"Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect availability.","cveId":"CVE-2025-66323","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"huawei","product":"harmonyos","affectedVersions":["5.0.1","5.1.0","6.0.0"],"cwes":["CWE-358"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://consumer.huawei.com/en/support/bulletin/2025/12/","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00081,"epssPercentile":0.00168,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2025-12-08T08:15:53.780Z","addedAt":"2026-10-07T20:39:31.177Z","updatedAt":"2026-10-07T20:39:31.177Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66323","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2025-66323","note":"authoritative record"}]},{"id":"4161adf7-d9c5-42c8-b454-ee5b729ac5d7","slug":"cve-2025-58308","externalId":"CVE-2025-58308","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2025-58308 — Vulnerability of improper criterion security check in the call module.","description":"Vulnerability of improper criterion security check in the call module.\nImpact: Successful exploitation of this vulnerability may cause features to perform abnormally.","cveId":"CVE-2025-58308","cvssScore":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","severity":"low","vendor":"huawei","product":"harmonyos","affectedVersions":["5.0.1","5.1.0","6.0.0"],"cwes":["CWE-358"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://consumer.huawei.com/en/support/bulletin/2025/11/","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00084,"epssPercentile":0.00255,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2025-11-28T04:16:00.650Z","addedAt":"2026-10-08T10:39:33.930Z","updatedAt":"2026-10-08T10:39:33.930Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58308","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2025-58308","note":"authoritative record"}]},{"id":"022aac4f-9524-4c5f-a96b-5a907c64eb1f","slug":"cve-2025-62585","externalId":"CVE-2025-62585","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2025-62585 — Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.","description":"Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.","cveId":"CVE-2025-62585","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","severity":"high","vendor":"navercorp","product":"whale","affectedVersions":["< 4.33.325.17"],"cwes":["CWE-358"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cve.naver.com/detail/cve-2025-62585.html","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00374,"epssPercentile":0.29227,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2025-10-16T07:15:33.963Z","addedAt":"2026-10-08T12:39:33.784Z","updatedAt":"2026-10-08T12:39:33.784Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62585","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2025-62585","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":28,"totalPages":2,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:53:02.982Z","durationMs":35,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-358"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}