{"success":true,"data":{"threats":[{"id":"0d742810-8759-4994-9ae5-96c427d14e82","slug":"cve-2026-61430","externalId":"GHSA-qg25-6gc4-48mg","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure","description":"## Summary\n\nPraisonAI's `web_crawl` agent tool performs a server-side HTTP fetch of an agent/attacker-influenced URL. SSRF is meant to be prevented by `_is_safe_crawl_url()`, which resolves the hostname and rejects private/loopback/link-local IPs **at validation time**. The validated value is the URL *string* (not a pinned IP); the fetch backend then **re-resolves the hostname at connection time**. Because validation and connection perform two independent DNS resolutions, a **DNS-rebinding** domain that returns a public IP during validation and an internal IP during the fetch fully bypasses the guard, and the internal HTTP response body is returned to the caller.\n\nThis is **SSRF with internal response disclosure (read-back)** — not blind SSRF. Runtime-confirmed against PraisonAI 4.6.63; the crawl response returned the controlled internal markers `PRAISONAI_INTERNAL_SECRET_CANARY_7f3a91` / `FAKE_INTERNAL_TOKEN_DO_NOT_USE_7f3a91`. Severity High. Reachable by any actor who can influence the URL an agent crawls (e.g. a chat/bot/agent surface).\n\n## Details\n\n### Affected component\n- Package: `praisonaiagents` (PraisonAI), version **4.6.63**.\n- File: `src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py`; tool `web_crawl` / `crawl_web` (part of the default bot tool set).\n\n### Vulnerable code / root cause\n\n**Code point 1 — check-time-only DNS validation, no IP pinning**\n\nPath:\n`src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py`\n\nFunction:\n`_is_safe_crawl_url`\n\nSnippet:\n```python\nfor info in socket.getaddrinfo(hostname, None):          # resolve at CHECK time\n    ip = ipaddress.ip_address(info[4][0])\n    if (ip.is_loopback or ip.is_private or ip.is_link_local\n            or ip.is_multicast or ip.is_unspecified):\n        return False\nreturn True\n```\nIssue: the guard validates the hostname by resolving it **once at check time**. It does not pin the resolved IP and does not return/forward that IP to the HTTP client. Any later resolution can differ.\n\n**Code point 2 — guard runs, then the URL *string* is handed to the backend**\n\nFunction:\n`web_crawl`\n\nSnippet:\n```python\nfor u in raw_url_list:\n    if _is_safe_crawl_url(u):       # validate the URL string\n        url_list.append(u)\n...\nresults = _crawl_with_httpx(url_list)   # or _crawl_with_crawl4ai(url_list)\n```\nIssue: attacker-controlled input (`urls`) is validated as a string; the backend then fetches that string and **re-resolves DNS independently** of the guard. There is no shared, pinned IP between check and fetch.\n\n**Code point 3 — `_crawl_with_httpx` backend re-resolves (redirect re-validation does not stop rebinding)**\n\nFunction:\n`_crawl_with_httpx`\n\nSnippet:\n```python\nwith httpx.Client(follow_redirects=False, timeout=30.0) as client:\n    for _ in range(max_redirects + 1):\n        if not _is_safe_crawl_url(current):   # re-resolves hostname (CHECK)\n            raise ValueError(\"Redirect target failed SSRF validation\")\n        response = client.get(current)        # resolves AGAIN at CONNECT\n```\nIssue: even with per-hop redirect re-validation, `_is_safe_crawl_url(current)` and `client.get(current)` are **two separate DNS resolutions** of the same hostname. A rebinding domain answers public to the check and internal to the connect → TOCTOU bypass. No IP pinning.\n\n**Code point 4 — urllib fallback (same function), no per-hop guard**\n\nSnippet:\n```python\nimport urllib.request\nwith urllib.request.urlopen(url, timeout=30) as response:   # re-resolves + auto-follows redirects\n    content = response.read().decode('utf-8', errors='ignore')\n```\nIssue: when `httpx` is not installed, this fallback inside `_crawl_with_httpx` fetches the URL and auto-follows redirects with no per-hop/per-connect validation. (Results from this function are labelled `\"provider\": \"httpx\"` regardless of which path runs.)\n\n**Code point 5 — crawl4ai/Chromium backend (confirmed addendum)**\n\nThe crawl4ai backend (`_crawl_with_crawl4ai` → `crawler.arun(url=url)`, headless Chromium) is also runtime-confirmed affected (browser re-resolves DNS / follows redirects with no per-connect guard). To keep this report focused on the `web_crawl` SSRF guard, the backend-specific evidence is in `SSRF-04_Crawl4AI_SSRF_Backend_Addendum.md`.\n\n### Attack flow\n1. Attacker controls a hostname (e.g. `rebind.lab`) whose authoritative DNS rebinds.\n2. Lookup #1 (the guard) → a public IP → `_is_safe_crawl_url()` returns true.\n3. The backend re-resolves → the attacker's DNS now answers an internal/private IP (cloud metadata, loopback, internal service).\n4. The backend connects to the internal service and returns its body to the caller → internal data disclosure.\n\n### Why existing protection is bypassed\n- The guard validates the hostname, not a pinned IP; check and connect resolve independently → DNS rebinding (TOCTOU) defeats it on every backend.\n- Redirect re-validation (httpx path) re-checks the *hostname* but still re-resolves at connect, so it does not stop rebinding; the urllib fallback and crawl4ai backends have no per-hop guard at all.\n\n### Security boundary\nThe server-side fetch reaches internal/loopback/metadata services not exposed to the attacker and returns their content (CVSS Scope: Changed). Reachable wherever an agent can be induced to crawl an attacker-supplied URL (PR:L). An unauthenticated single-request path to `web_crawl` read-back was not found in 4.6.63 (so PR:N / Critical is not claimed).\n\n## Proof of Concept\n\n### Environment\nReal PraisonAI 4.6.63 in a local Docker runtime; a controlled internal canary service (Docker-internal only, not published) returns synthetic markers; a controlled DNS responder implements rebinding for `rebind.lab`. No public host / real metadata / real secret. Runnable assets: `PraisonAI-Runtime-Repro\\runtime-files\\`.\n\n### Steps to reproduce\n1. Burp Repeater tab `PRAI-05-01-DNS-Rebind-Trigger` → `127.0.0.1:18080`:\n```http\nPOST /tool/web_crawl HTTP/1.1\nHost: 127.0.0.1:18080\nContent-Type: application/json\n\n{\"url\":\"http://rebind.lab:8081/secret\"}\n```\n2. Send (`PRAI-05-02-DNS-Rebind-Secret-Readback` captures the response). If a send returns the \"blocked\" error, the rebinding DNS auto-resets (~3s) — resend.\n3. Redirect variant: `PRAI-05-03-Redirect-Trigger` / `PRAI-05-04-Redirect-Secret-Readback` send `{\"url\":\"http://redirector:8082/redirect-to-internal\"}`.\n\n### Expected result\nA safe SSRF guard refuses destinations that resolve to internal/private IPs regardless of DNS timing or redirects, and does not return internal content.\n\n### Actual result\nHTTP 200 with the internal body in the crawl result. Primary evidence is the `provider: \"httpx\"` backend returning the internal canary via DNS rebinding:\n```json\n{\"input_url\":\"http://rebind.lab:8081/secret\",\n \"result\":{\"content\":\"{ ... \\\"secret\\\": \\\"PRAISONAI_INTERNAL_SECRET_CANARY_7f3a91\\\", \\\"token\\\": \\\"FAKE_INTERNAL_TOKEN_DO_NOT_USE_7f3a91\\\" ... }\",\"provider\":\"httpx\"}}\n```\nThe redirect variant returns the same internal markers via a redirect chain (`provider: \"httpx\"`).\n\n### Screenshots\n\n**DNS rebinding read-back**\n\nThe attacker-controlled `rebind.lab` URL is accepted by `web_crawl`, and the PraisonAI response contains the internal canary response body.\n\n<img width=\"1543\" height=\"785\" alt=\"01-DNS-Rebind-Burp-Readback\" src=\"https://github.com/user-attachments/assets/e86e95dd-3d3a-4bef-b1c6-cb897234a212\" />\n\n**DNS rebinding runtime evidence**\n\nThe runtime log shows `rebind.lab` first resolving to an allowed/public IP during validation (`guard-pass`), then resolving to an internal Docker IP during the actual fetch (`fetch-hit`). The internal canary receives `GET /secret` from the PraisonAI container.\n\n<img width=\"1654\" height=\"828\" alt=\"02-DNS-Rebind-DNS-Log-And-Internal-Hit\" src=\"https://github.com/user-attachments/assets/f1d28046-de34-48f0-9bee-bbe26e598d5f\" />\n\n**Redirect-based SSRF read-back**\n\nThe attacker-controlled redirector URL is accepted by `web_crawl`. PraisonAI follows the redirect and returns the internal canary response body containing `PRAISONAI_INTERNAL_SECRET_CANARY_7f3a91`.\n\n<img width=\"1540\" height=\"772\" alt=\"03-Redirect-Burp-Readback\" src=\"https://github.com/user-attachments/assets/79eec159-4b9f-44be-a9eb-b15aba35ead8\" />\n\n**Redirect chain runtime evidence**\n\nThe controlled redirector returns `302 -> http://internal-canary:8081/secret`, and the internal canary receives `GET /secret`, confirming that the server-side client followed the redirect into the internal network.\n\n<img width=\"1637\" height=\"894\" alt=\"04-Redirect-Internal-Hit-Log\" src=\"https://github.com/user-attachments/assets/1c503e30-9d01-4d32-8658-497f755a969e\" />\n\n### Reproduction assets\n\nThe attached archive contains the local Docker runtime used to reproduce the issue with controlled canary services only. It does not contain real secrets, real cloud metadata access, or third-party API keys.\n\n[PraisonAI-Runtime-Repro.zip](https://github.com/user-attachments/files/29142379/PraisonAI-Runtime-Repro.zip)\n\n## Impact\nSSRF against internal/loopback/cloud-metadata endpoints with **disclosure of internal HTTP responses** (read-back) to the attacker. Bypasses the project's SSRF protection on every fetch backend.\n\n## Suggested remediation\n1. Resolve the host once, reject all returned records that are private/loopback/link-local/ULA/CGNAT/metadata, then **connect to that exact validated IP** (pin it; send the original `Host`). Do not let the HTTP client / browser re-resolve.\n2. Apply the same validation + IP pinning to every backend (httpx, urllib fallback, crawl4ai) and every redirect hop.\n3. Disable automatic redirect following (or cap + re-validate each hop with pinning).\n4. Treat IPv4-mapped IPv6, decimal/octal/hex IPs, and CGNAT/non-global ranges as unsafe.","cveId":"CVE-2026-61430","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","severity":"high","vendor":"PyPI","product":"praisonaiagents","affectedVersions":["pkg:pypi/praisonaiagents < 1.6.78"],"cwes":["CWE-200","CWE-367","CWE-918"],"tags":["osv","osv:ghsa-qg25-6gc4-48mg","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-qg25-6gc4-48mg","type":"advisory","title":"OSV GHSA-qg25-6gc4-48mg"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qg25-6gc4-48mg","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61430","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62169","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-dns-rebinding-ssrf-via-web-crawl","type":"other","title":"OSV web"}],"epssScore":0.00348,"epssPercentile":0.26274,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:36:50.000Z","addedAt":"2026-10-08T18:42:42.814Z","updatedAt":"2026-10-08T18:42:42.814Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61430","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61430","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-qg25-6gc4-48mg"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-qg25-6gc4-48mg"}]},{"id":"acef84cb-420c-48b9-aa2a-77d7e2bc3277","slug":"cve-2026-61429","externalId":"GHSA-6g59-gm2v-qhvq","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: Crawl4AI/Chromium backend is also affected by the `web_crawl` SSRF validation bypass","description":"## Summary\n\nThe DNS-rebinding / redirect SSRF bypass in PRAI-05 is **not limited to the httpx/urllib backend**. When `crawl4ai` (headless Chromium via Playwright) is installed, `web_crawl` auto-selects `provider=crawl4ai`, and the headless browser re-resolves DNS and follows redirects on its own — with no per-connection SSRF guard. Runtime-confirmed read-back of the internal canary via both DNS rebinding and redirect (`provider: \"crawl4ai\"`). Status: runtime-confirmed addendum to PRAI-05.\n\n## Details\n\n### Affected component\n- Package `praisonaiagents` 4.6.63. Backend selected when `crawl4ai`+Playwright are installed.\n- Files: `src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py` (`_crawl_with_crawl4ai`) and `src/praisonai-agents/praisonaiagents/tools/crawl4ai_tools.py` (standalone crawl wrappers).\n\n### Vulnerable code / root cause\n\nPath:\n`src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py`\n\nFunction:\n`_crawl_with_crawl4ai`\n\nSnippet:\n```python\nasync with AsyncWebCrawler() as crawler:\n    for url in urls:\n        result = await crawler.arun(url=url)   # headless browser: re-resolves DNS, follows redirects\n```\n\nPath:\n`src/praisonai-agents/praisonaiagents/tools/crawl4ai_tools.py`\n\nFunction:\n`Crawl4AITools.crawl` / `crawl4ai`\n\nSnippet:\n```python\nresult = await crawler.arun(url=url, config=config)   # no _is_safe_crawl_url / no per-connect validation\n```\n\nIssue: the only SSRF check is the single pre-fetch `_is_safe_crawl_url()` on the initial URL string in `web_crawl()` (see PRAI-05). The headless browser then resolves and connects independently and follows redirects in-browser — no resolved-IP pinning, no per-hop/per-connect validation. Input (`urls`) is attacker/agent-controlled; the sink is `crawler.arun(url=...)`; the guard is bypassed by DNS rebinding (TOCTOU) and by redirects (followed in-browser).\n\n### Attack flow / Why bypassed / Security boundary\nIdentical to PRAI-05: TOCTOU between the guard's resolution and the browser's connection; redirects followed in-browser; internal response returned as crawl `content`. See PRAI-05.\n\n## Proof of Concept\n\n### Environment\n`crawl4ai` + Playwright Chromium installed in a dedicated runtime container (`127.0.0.1:18081`), same controlled internal canary + rebinding DNS. Runnable assets: `PraisonAI-Runtime-Repro\\runtime-files\\` (`docker-compose.crawl.yml`).\n\n### Steps to reproduce\n1. `SSRF-04-01-Crawl4AI-DNS-Rebind-Trigger` → `127.0.0.1:18081`:\n```http\nPOST /tool/web_crawl HTTP/1.1\nHost: 127.0.0.1:18081\nContent-Type: application/json\n\n{\"url\":\"http://rebind.lab:8081/secret\"}\n```\n2. Redirect variant `SSRF-04-03-Crawl4AI-Redirect-Readback`: `{\"url\":\"http://redirector:8082/redirect-to-internal\"}`.\n\n### Expected result\nThe crawl backend refuses internal destinations regardless of DNS timing/redirects.\n\n### Actual result\nHTTP 200, `\"provider\":\"crawl4ai\"`, response `content` contains `PRAISONAI_INTERNAL_SECRET_CANARY_7f3a91` + `FAKE_INTERNAL_TOKEN_DO_NOT_USE_7f3a91` for both the DNS-rebinding and the redirect payload.\n\n### Screenshots\n\n**Crawl4AI DNS rebinding read-back**\n\nThe attacker-controlled `rebind.lab` URL is accepted by the Crawl4AI-backed `web_crawl` endpoint. PraisonAI returns the internal canary response body containing `PRAISONAI_INTERNAL_SECRET_CANARY_7f3a91`.\n\n<img width=\"1542\" height=\"763\" alt=\"01-Crawl4AI-Burp-Readback\" src=\"https://github.com/user-attachments/assets/a03b3a1c-e382-4f67-8ea6-b766dceb4a69\" />\n\n**Crawl4AI DNS rebinding runtime evidence**\n\nThe runtime log shows the Crawl4AI/Chromium backend resolving `rebind.lab` to an internal Docker IP during the fetch phase. The internal canary receives `GET /secret` from a headless Chrome user agent.\n\n<img width=\"1659\" height=\"946\" alt=\"02-Crawl4AI-DNS-Log-And-Internal-Hit\" src=\"https://github.com/user-attachments/assets/d93db090-3e39-43d0-af3b-5d1d8f614db8\" />\n\n**Crawl4AI redirect read-back**\n\nThe attacker-controlled redirector URL is accepted by the Crawl4AI-backed endpoint. PraisonAI follows the redirect and returns the internal canary response body.\n\n<img width=\"1544\" height=\"771\" alt=\"03-Crawl4AI-Redirect-Readback\" src=\"https://github.com/user-attachments/assets/7d05c8aa-5bda-45bc-b94c-bef0bdcf055c\" />\n\n**Crawl4AI redirect runtime evidence**\n\nThe controlled redirector returns `302 -> http://internal-canary:8081/secret`, and the internal canary receives `GET /secret` from the Crawl4AI/Chromium backend.\n\n<img width=\"1590\" height=\"920\" alt=\"04-Crawl4AI-Redirect-Internal-Hit-Log\" src=\"https://github.com/user-attachments/assets/dd9c0fec-3583-43ab-b83c-4470fa6aa409\" />\n\n\n## Impact\nSame class as PRAI-05: read-back SSRF to internal/metadata services, now on the crawl4ai backend. Broadens the affected surface (the flaw is in the shared validate-without-pinning design, not one backend).\n\n## Suggested remediation\nResolve-once + IP-pin + per-connect validation must also cover the crawl4ai backend (constrain the headless browser to the validated IP, or allowlist crawl destinations).","cveId":"CVE-2026-61429","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","severity":"high","vendor":"PyPI","product":"praisonaiagents","affectedVersions":["pkg:pypi/praisonaiagents < 1.6.78"],"cwes":["CWE-200","CWE-367","CWE-918"],"tags":["osv","osv:ghsa-6g59-gm2v-qhvq","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-6g59-gm2v-qhvq","type":"advisory","title":"OSV GHSA-6g59-gm2v-qhvq"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6g59-gm2v-qhvq","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61429","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-ssrf-via-crawl4ai-chromium-backend","type":"other","title":"OSV web"}],"epssScore":0.00348,"epssPercentile":0.26274,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T20:22:17.000Z","addedAt":"2026-10-08T00:42:50.063Z","updatedAt":"2026-10-08T00:42:50.063Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61429","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61429","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-6g59-gm2v-qhvq"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-6g59-gm2v-qhvq"}]},{"id":"626445f1-5b45-4076-b9ea-382a1c34b660","slug":"cve-2026-107276","externalId":"CVE-2026-107276","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107276 — MISP contains a race condition in the email-based one-time password (OTP) login flow.","description":"MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect.\n\nPreconditions:\n\n- The target MISP instance has email OTP login enabled.\n\n- The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering).\n\n- The attacker can issue two HTTP POST requests in close temporal proximity.\n\nImpact:\n\n- The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions.\n\n- This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted.\n\nAffected versions: <2.5.48","cveId":"CVE-2026-107276","cvssScore":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-362","CWE-367"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/MISP/MISP/commit/ba95e67d5","type":"advisory","title":"5a6e4751-2f3f-4070-9419-94fb35b644e8"}],"epssScore":0.00213,"epssPercentile":0.10634,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:47.213Z","addedAt":"2026-10-07T16:39:32.766Z","updatedAt":"2026-10-07T22:39:36.401Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107276","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107276","note":"authoritative record"}]},{"id":"1651320f-aa6f-4cee-87cc-fd181f5a0a37","slug":"cve-2026-103435","externalId":"CVE-2026-103435","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103435 — Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at wr…","description":"Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a project file with a symlink, causing Claude Code to follow the symlink and write its output to an arbitrary file outside the project sandbox. Exploitation required the ability to win a race condition against the write operation and write access to the shared workspace, enabling a lower-privileged attacker to redirect benign edits to sensitive files (e.g., shell configuration) in a higher-privileged session.\n\nUsers on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.\n\nThank you to hackerone.com/c_h4ck_0 for reporting this issue.","cveId":"CVE-2026-103435","cvssScore":7.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-22","CWE-61","CWE-367"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-5j29-h97v-84ch","type":"advisory","title":"98a01053-8a31-4f6d-9aa9-252be161adc6"}],"epssScore":0.00251,"epssPercentile":0.15086,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T13:17:16.690Z","addedAt":"2026-10-07T14:39:35.072Z","updatedAt":"2026-10-07T16:39:32.117Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103435","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103435","note":"authoritative record"}]},{"id":"dc9e8f8f-6652-4a86-bb4f-2a2f50f558c6","slug":"cve-2026-89430","externalId":"CVE-2026-89430","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-89430 — Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created.","description":"Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to `git push`, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them.","cveId":"CVE-2026-89430","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-367","CWE-918"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.gitea.com/release-of-28.0.0/","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39010","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39426","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v28.0.0","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-hcgw-r9gf-8mph","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"}],"epssScore":0.0019,"epssPercentile":0.07946,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:34.297Z","addedAt":"2026-10-06T20:39:33.462Z","updatedAt":"2026-10-07T22:39:36.234Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89430","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-89430","note":"authoritative record"}]},{"id":"fb5d2ace-6d7d-49cb-8433-e6fcf552e6c4","slug":"cve-2026-106451","externalId":"CVE-2026-106451","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106451 — yawkat LZ4 Java provides LZ4 compression for Java.","description":"yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4.","cveId":"CVE-2026-106451","cvssScore":7.3,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"Maven","product":"at.yawk.lz4:lz4-java","affectedVersions":["pkg:maven/at.yawk.lz4/lz4-java < 1.11.4","pkg:maven/org.lz4/lz4-java >= 1.7.0, <= 1.8.1"],"cwes":["CWE-367","CWE-377"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-mcr4-qmvw-px4g","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-mcr4-qmvw-px4g","type":"advisory","title":"OSV GHSA-mcr4-qmvw-px4g"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106451","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/yawkat/lz4-java","type":"vendor","title":"OSV package"}],"epssScore":0.00083,"epssPercentile":0.00225,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:27.173Z","addedAt":"2026-10-06T20:39:33.109Z","updatedAt":"2026-10-08T00:42:49.585Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106451","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106451","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-MCR4-QMVW-PX4G"}]},{"id":"4e559355-6699-4bfd-b1db-fc489c52df35","slug":"cve-2026-101029","externalId":"CVE-2026-101029","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-101029 — Gitea's repository migration and pull mirror egress checks could be bypassed with a hostname that returns multiple DNS answers, because the address…","description":"Gitea's repository migration and pull mirror egress checks could be bypassed with a hostname that returns multiple DNS answers, because the address that was validated was not necessarily the address Git later connected to. A low-privileged user who can create migrations or mirrors could direct the server to internal services, reading from and writing to reachable internal Git or HTTP endpoints. Content from internal responses could additionally be disclosed through migration and mirror error messages.","cveId":"CVE-2026-101029","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-209","CWE-367","CWE-918"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.gitea.com/release-of-28.0.0/","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39010","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39426","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v28.0.0","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-6g2h-xpg3-rm48","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"}],"epssScore":0.00171,"epssPercentile":0.05875,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:08.647Z","addedAt":"2026-10-06T20:39:32.608Z","updatedAt":"2026-10-07T22:39:36.172Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101029","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-101029","note":"authoritative record"}]},{"id":"121f441c-c6e9-42ac-b35d-e652f9b1a7d3","slug":"cve-2026-106413","externalId":"CVE-2026-106413","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106413 — Race condition in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI el…","description":"Race condition in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","cveId":"CVE-2026-106413","cvssScore":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-367"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/553336689","type":"advisory","title":"Permissions Required"}],"epssScore":0.00139,"epssPercentile":0.02806,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:10.977Z","addedAt":"2026-10-06T20:39:32.303Z","updatedAt":"2026-10-07T14:39:33.635Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106413","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106413","note":"authoritative record"}]},{"id":"264ab68f-df91-48bf-be5a-6b445c4a7fc9","slug":"cve-2026-106412","externalId":"CVE-2026-106412","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106412 — Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and lev…","description":"Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106412","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-367"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/520755056","type":"advisory","title":"Permissions Required"}],"epssScore":0.00236,"epssPercentile":0.13435,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:10.860Z","addedAt":"2026-10-06T20:39:32.296Z","updatedAt":"2026-10-07T14:39:33.624Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106412","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106412","note":"authoritative record"}]},{"id":"2539eb92-19c1-496c-b627-888926d62f3b","slug":"cve-2026-106405","externalId":"CVE-2026-106405","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106405 — Race condition in CustomTabs in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass web origin policy via a co-in…","description":"Race condition in CustomTabs in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Medium)","cveId":"CVE-2026-106405","cvssScore":6,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-367"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"advisory","title":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/517150523","type":"advisory","title":"chrome-cve-admin@google.com"}],"epssScore":0.0009,"epssPercentile":0.00422,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:10.073Z","addedAt":"2026-10-06T20:39:32.241Z","updatedAt":"2026-10-08T16:39:34.829Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106405","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106405","note":"authoritative record"}]},{"id":"2f1c1396-2cb8-40f1-b5cc-ce6f51ef2af6","slug":"cve-2026-106300","externalId":"CVE-2026-106300","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106300 — Race condition in CacheStorage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read m…","description":"Race condition in CacheStorage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106300","cvssScore":4.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-367"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/500106110","type":"advisory","title":"Permissions Required"}],"epssScore":0.00161,"epssPercentile":0.047,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:58.030Z","addedAt":"2026-10-06T20:39:31.431Z","updatedAt":"2026-10-07T18:39:30.402Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106300","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106300","note":"authoritative record"}]},{"id":"71da05de-50b8-4155-b33c-4e56918c70e8","slug":"cve-2026-106207","externalId":"CVE-2026-106207","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106207 — Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted H…","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106207","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-367"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/554619028","type":"advisory","title":"Permissions Required"}],"epssScore":0.00292,"epssPercentile":0.19983,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:47.077Z","addedAt":"2026-10-06T20:39:30.692Z","updatedAt":"2026-10-08T12:39:41.024Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106207","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106207","note":"authoritative record"}]},{"id":"fa27cac4-d5a5-4577-8347-218475f9be49","slug":"cve-2026-93315","externalId":"CVE-2026-93315","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93315 — When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup.","description":"When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build.","cveId":"CVE-2026-93315","cvssScore":5.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-367"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/moby/buildkit/releases/tag/v0.33.1","type":"advisory","title":"security@docker.com"},{"url":"https://github.com/moby/buildkit/security/advisories/GHSA-2f5p-x9ph-g97x","type":"advisory","title":"security@docker.com"}],"epssScore":0.00096,"epssPercentile":0.00666,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T22:16:58.820Z","addedAt":"2026-10-05T23:50:40.441Z","updatedAt":"2026-10-06T15:50:58.836Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93315","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93315","note":"authoritative record"}]},{"id":"7d85178e-fc44-463e-a3d0-57063c43ae09","slug":"cve-2026-105743","externalId":"CVE-2026-105743","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105743 — Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem.","description":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.91.0 until 2.132.0, validate_url_safety in docling/backend/utils/image_resource_loader.py validates a hostname with a single IPv4 lookup and then allows the HTTP client to resolve and parse the original URL again, permitting DNS rebinding, mixed public and internal address records, and backslash authority parser disagreement to reach internal services. HTMLBackendOptions(render_page=True) also allows HTTP and HTTPS browser requests without validating their resolved destination. Exploitation requires remote fetching to be enabled, and response content is exposed only when it is decoded as an image or passively rendered in a page screenshot. This issue is fixed in 2.132.0.","cveId":"CVE-2026-105743","cvssScore":5.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","severity":"medium","vendor":"docling","product":"docling","affectedVersions":[">= 2.91.0, < 2.132.0","pkg:pypi/docling >= 2.91.0, < 2.132.0","pkg:pypi/docling-slim >= 2.92.0, < 2.132.0"],"cwes":["CWE-367","CWE-918"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed","osv","osv:ghsa-pc36-qwjq-x68c","ecosystem:pypi","osv:pysec-2026-4190"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/docling-project/docling/commit/5e469137f275ffc443306a30d12a3a45bceb80fb","https://github.com/docling-project/docling/pull/4420","https://github.com/docling-project/docling/security/advisories/GHSA-pc36-qwjq-x68c"],"references":[{"url":"https://github.com/docling-project/docling/commit/5e469137f275ffc443306a30d12a3a45bceb80fb","type":"patch","title":"OSV fix"},{"url":"https://github.com/docling-project/docling/pull/4420","type":"patch","title":"OSV fix"},{"url":"https://github.com/docling-project/docling/releases/tag/v2.132.0","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/docling-project/docling/security/advisories/GHSA-pc36-qwjq-x68c","type":"patch","title":"OSV fix"},{"url":"https://osv.dev/vulnerability/GHSA-pc36-qwjq-x68c","type":"advisory","title":"OSV GHSA-pc36-qwjq-x68c"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105743","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/docling-project/docling","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4190","type":"advisory","title":"OSV PYSEC-2026-4190"}],"epssScore":0.0019,"epssPercentile":0.07925,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T22:16:57.030Z","addedAt":"2026-10-05T23:50:40.365Z","updatedAt":"2026-10-08T12:42:40.438Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105743","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105743","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-PC36-QWJQ-X68C"}]},{"id":"26873c75-0d22-41f4-9731-fd971b4320b6","slug":"cve-2026-105647","externalId":"CVE-2026-105647","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105647 — Ghost is a Node.js content management system.","description":"Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This issue is fixed in version 6.65.0.","cveId":"CVE-2026-105647","cvssScore":4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N","severity":"medium","vendor":"npm","product":"ghost","affectedVersions":["pkg:npm/ghost >= 6.54.1, < 6.65.0"],"cwes":["CWE-367","CWE-918"],"tags":["nvd","status:received","status:deferred","osv","osv:ghsa-322m-ff4g-9vx9","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/TryGhost/Ghost/commit/3f8594eb53de883ac017545c358f59039cb152de","type":"other","title":"OSV web"},{"url":"https://github.com/TryGhost/Ghost/pull/30918","type":"other","title":"OSV web"},{"url":"https://github.com/TryGhost/Ghost/releases/tag/v6.65.0","type":"other","title":"OSV web"},{"url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-322m-ff4g-9vx9","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-322m-ff4g-9vx9","type":"advisory","title":"OSV GHSA-322m-ff4g-9vx9"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105647","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/TryGhost/Ghost","type":"vendor","title":"OSV package"}],"epssScore":0.0023,"epssPercentile":0.12677,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T20:17:13.157Z","addedAt":"2026-10-05T21:50:40.929Z","updatedAt":"2026-10-08T00:42:49.452Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105647","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105647","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-322M-FF4G-9VX9"}]},{"id":"5ec2080a-642f-4bc3-b110-b80e2b58aec0","slug":"cve-2026-77804","externalId":"CVE-2026-77804","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-77804 — In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists …","description":"In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root certificate into the Local Computer certificate store. Fiddler writes the certificate to a temporary file in a user-writable location and then launches the external TrustCert helper application, which elevates and imports the certificate from that file. A local threat actor with low privileges who replaces the temporary file between the time it is written and the time the elevated helper reads it can cause an attacker-supplied root certificate to be installed in the Local Computer Trusted Root Certification Authorities store, enabling subsequent interception and modification of TLS-protected traffic on the machine. Successful exploitation requires the user to initiate the certificate trust operation and approve the elevation prompt.","cveId":"CVE-2026-77804","cvssScore":6.6,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-367"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://docs.telerik.com/fiddler/knowledge-base/kb-security-root-certificate-installation-toctou-cve-2026-77804","type":"advisory","title":"security@progress.com"}],"epssScore":0.00058,"epssPercentile":0.00004,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T13:16:54.590Z","addedAt":"2026-10-05T13:50:41.027Z","updatedAt":"2026-10-06T18:39:26.648Z","epssUpdatedAt":"2026-10-06T12:00:23.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77804","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-77804","note":"authoritative record"}]},{"id":"e8a0dd96-21cb-4fdc-944b-93e633ad0569","slug":"cve-2026-105163","externalId":"CVE-2026-105163","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105163 — A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2.","description":"A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and 2.4.0-rc.1 is able to resolve this issue. The patch is identified as bee99c6cd6ca81878acca2940a2f0a02169fc208. You should upgrade the affected component.","cveId":"CVE-2026-105163","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"Go","product":"github.com/crossplane/crossplane-runtime/v2","affectedVersions":["pkg:golang/github.com/crossplane/crossplane-runtime/v2 >= 2.4.0-rc.0, < 2.4.0-rc.1","pkg:golang/github.com/crossplane/crossplane-runtime/v2 >= 2.3.0, < 2.3.3","pkg:golang/github.com/crossplane/crossplane-runtime/v2 >= 2.3.0, < 2.3.3 || >= 2.4.0-rc.0, < 2.4.0-rc.1"],"cwes":["CWE-362","CWE-367","CWE-345"],"tags":["nvd","status:received","osv","osv:ghsa-mf7q-r4rv-jv94","ecosystem:go","osv:go-2026-6302","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/crossplane/crossplane-runtime/pull/1038","https://github.com/crossplane/crossplane-runtime/commit/bee99c6cd6ca81878acca2940a2f0a02169fc208"],"references":[{"url":"https://github.com/advisories/GHSA-mf7q-r4rv-jv94","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/crossplane/crossplane-runtime/","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/crossplane/crossplane-runtime/commit/bee99c6cd6ca81878acca2940a2f0a02169fc208","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/crossplane/crossplane-runtime/pull/1038","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/crossplane/crossplane-runtime/releases/tag/v2.2.3","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-105163","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413395","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413395/cti","type":"advisory","title":"cna@vuldb.com"},{"url":"https://osv.dev/vulnerability/GHSA-mf7q-r4rv-jv94","type":"advisory","title":"OSV GHSA-mf7q-r4rv-jv94"},{"url":"https://github.com/crossplane/crossplane-runtime/security/advisories/GHSA-mf7q-r4rv-jv94","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/crossplane/crossplane-runtime","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/GO-2026-6302","type":"advisory","title":"OSV GO-2026-6302"},{"url":"https://github.com/crossplane/crossplane-runtime/releases/tag/v2.3.3","type":"other","title":"OSV web"}],"epssScore":0.00322,"epssPercentile":0.2323,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-04T22:16:58.763Z","addedAt":"2026-10-04T23:50:40.031Z","updatedAt":"2026-10-06T15:50:56.716Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105163","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105163","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-MF7Q-R4RV-JV94"}]},{"id":"021646d1-6167-43d3-a95d-9d5d20d5cfa2","slug":"cve-2026-105130","externalId":"CVE-2026-105130","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105130 — LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers…","description":"LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls.","cveId":"CVE-2026-105130","cvssScore":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-367"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/laradashboard/laradashboard","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Auth/RegisterController.php#L175-L188","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/Auth/RegistrationGuardService.php#L77-L105","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/laradashboard/laradashboard/commit/1bc7b7e2d32dd0bbee8f39a7ed8a3316ae657d50","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/laradashboard/laradashboard/pull/343","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/laradashboard/laradashboard/security/advisories/GHSA-gw6g-9wx9-3fpj","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.vulncheck.com/advisories/laradashboard-1.4.0-before-1.4.8-race-condition-bypasses-per-ip-registration-limit","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00223,"epssPercentile":0.11884,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-04T00:16:36.893Z","addedAt":"2026-10-04T01:50:39.759Z","updatedAt":"2026-10-05T17:50:42.484Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105130","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105130","note":"authoritative record"}]},{"id":"1c1b6f33-3650-42cd-8c2d-6d37d09f14eb","slug":"cve-2026-104474","externalId":"CVE-2026-104474","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104474 — OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a no…","description":"OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.","cveId":"CVE-2026-104474","cvssScore":5.4,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-367"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/litespeedtech/openlitespeed/blob/v1.9.2/dist/admin/misc/lsup.sh#L538","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/litespeedtech/openlitespeed/commit/468523ce84388cea9ba6633c26517bc05b3e2bc1","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://openlitespeed.org/release-log/version-1-9-x/","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/openlitespeed-before-1.9.3-local-privilege-escalation-via-lsup-sh-auto-update","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00085,"epssPercentile":0.0027,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-03T00:16:35.413Z","addedAt":"2026-10-03T03:50:40.171Z","updatedAt":"2026-10-06T17:50:41.786Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104474","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104474","note":"authoritative record"}]},{"id":"1d9dc7d6-e7ef-4c14-b350-0d78eb10d649","slug":"cve-2026-47497","externalId":"CVE-2026-47497","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-47497 — NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing component where a guest VM user may cause improper ac…","description":"NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing component where a guest VM user may cause improper access by sending crafted data through a shared buffer. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","cveId":"CVE-2026-47497","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-367"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5861","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47497","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47497","type":"advisory","title":"psirt@nvidia.com"}],"epssScore":0.00101,"epssPercentile":0.00852,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:17:14.293Z","addedAt":"2026-09-30T17:50:47.842Z","updatedAt":"2026-10-01T05:50:42.532Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47497","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-47497","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":276,"totalPages":14,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T00:00:16.232Z","durationMs":42,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-367"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}