{"success":true,"data":{"threats":[{"id":"0c846a65-398e-4698-bd51-6e7fe2764865","slug":"cve-2026-107226","externalId":"GHSA-p2jm-6hj6-9rjg","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"AsyncHttpClient: Cookies received over plaintext HTTP can plant, overwrite or delete Secure cookies set over HTTPS","description":"### Impact\nThe cookie store ignores the scheme a `Set-Cookie` arrived on. draft-ietf-httpbis-rfc6265bis-22 (approved to obsolete RFC 6265, in the RFC Editor queue) Section 5.7 requires a user agent to ignore a cookie with the `Secure` attribute unless it arrived over a secure connection (step 13), and to ignore a non-Secure cookie from an insecure connection when it would overlay a Secure cookie the store already holds (step 16). Neither rule is implemented. The only `Secure` handling is on retrieval, where a Secure cookie is not sent over plaintext.\n\nSo anyone who can answer a plaintext request to a site can set, replace or delete the site's `Secure` cookies, and the next HTTPS request carries the attacker's value back inside TLS:\n\n```\nhttp://example.com   ->  Set-Cookie: SID=attacker-value; Secure; Path=/\nhttps://example.com  ->  Cookie: SID=attacker-value\n```\n\nThis does not need an attacker on the network path. A plaintext host under the same site reaches the HTTPS one by setting a domain cookie:\n\n```\nhttp://insecure.example.com  ->  Set-Cookie: SID=attacker-value; Secure; Domain=example.com; Path=/\nhttps://bank.example.com     ->  Cookie: SID=attacker-value\n```\n\nA plaintext `Set-Cookie` of the same name, domain and path overwrites a Secure cookie, and one with `Max-Age=0` deletes it. Depending on what the application does with the cookie, this is session fixation into the HTTPS session, an overwritten CSRF token, or the removal of a cookie the site relies on. Unlike GHSA-qjr7-w8pj-pmv9, which can only add a cookie, this replaces or deletes one, hence Integrity: High; the harm lands on the HTTPS site, hence Scope: Changed.\n\n### Affected versions\n* 3.x: up to and including 3.0.13\n* 2.x: from 2.1.0, when the cookie store was introduced, up to and including 2.16.1\n\n### Patches\nFixed in 3.0.14 on the 3.x line. A cookie with the `Secure` attribute is ignored unless the request was secure, and a non-Secure cookie from a request that did not use TLS is ignored when it would overlay a Secure cookie of the same name whose path its own path falls under. A plaintext response can therefore no longer plant, overwrite or delete a `Secure` cookie.\n\nWhen several cookies of one name match a request, the client sends only the first, so the order in which the store returns them decides which one is used. That order is now: on a secure request, cookies received in a secure context (HTTPS, WSS or plaintext loopback) first; then the request host's own cookies before cookies set for a parent domain; then, within one host, longer paths first. A plaintext attacker cannot outrank a cookie the site set over HTTPS by ordering or padding its own cookies, or by setting one before the site sets its own.\n\nPlaintext requests to `localhost`, or to an address literal that is a loopback address, count as secure, so a development server that sets `Secure` cookies over `http://localhost` gets them back. This is limited to the cookies such a server set itself: a `Secure` cookie that arrived over HTTPS is never sent over plaintext, loopback included, and a plaintext loopback port cannot overlay it. Numeric spellings that are not address literals, such as `127.0.0.256`, and names under `localhost` are not treated as loopback, because the client resolves them as names.\n\nThe 2.x line is end of life and will not receive a fix. Upgrade to 3.0.14.\n\n### Workarounds\nDo not share one `CookieStore` between plaintext and HTTPS origins that are not mutually trusted, including hosts under the same site. Disabling the cookie store also avoids it.\n\n### Details\n`ThreadSafeCookieStore.add(Uri, Cookie)` reduces the request to its host and path before storing, so the scheme never reaches the code that decides whether to keep a cookie. `get(Uri)` does read it, but only to leave `Secure` cookies out of plaintext requests.\n\nA narrower form survives the two storage rules on their own. The step 16 path test is one-way by design, so a plaintext `SID` for `Path=/` is legitimately stored beside a Secure `SID` for `Path=/account`, and both match a request under `/account`. The store returned matching cookies in hash order, and the client keeps only the first cookie of each name when it builds the request (`RequestBuilderBase.addCookieIfUnset`), so an attacker could decide which one was sent, for example by padding one plaintext response with filler cookies. The ordering described above closes it.\n\nThe fix does not stop an HTTPS host under the same site from setting a domain cookie for a name the request host never sets itself. Only a `__Host-` cookie name prefix prevents that, and the client does not enforce cookie name prefixes.\n\n### Attribution\n\nAI-assisted tools were used to support discovery and analysis.","cveId":"CVE-2026-107226","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","severity":"medium","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.14","pkg:maven/org.asynchttpclient/async-http-client >= 2.1.0, <= 2.16.1"],"cwes":["CWE-384","CWE-693"],"tags":["osv","osv:ghsa-p2jm-6hj6-9rjg","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-p2jm-6hj6-9rjg","type":"advisory","title":"OSV GHSA-p2jm-6hj6-9rjg"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-p2jm-6hj6-9rjg","type":"other","title":"OSV web"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/6ec7ee45034d154f502852a962d2891746fb82c1","type":"other","title":"OSV web"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:49:59.000Z","addedAt":"2026-10-08T18:42:42.551Z","updatedAt":"2026-10-08T18:42:42.551Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107226","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107226","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-p2jm-6hj6-9rjg"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-p2jm-6hj6-9rjg"}]},{"id":"d336c3d0-3ce0-42de-9159-7a188c780e56","slug":"cve-2026-107229","externalId":"CVE-2026-107229","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107229 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.16.0 until 3.0.14, ThreadSafeCookieStore incompletely validates cookie Domain attributes. Missing private-section and default public-suffix rules, absent A-label normalization, locale-sensitive lowercasing, public-suffix host-only handling, and numeric or IP host checks allow one origin to store a cookie later sent to another origin. Applications sharing one client across trust domains can therefore receive attacker-injected cookies and may be exposed to session fixation. This issue is fixed in version 3.0.14.","cveId":"CVE-2026-107229","cvssScore":4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-384","CWE-1275"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-qjr7-w8pj-pmv9","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00261,"epssPercentile":0.16373,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T21:17:14.613Z","addedAt":"2026-10-07T22:39:36.540Z","updatedAt":"2026-10-08T21:05:43.984Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107229","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107229","note":"authoritative record"}]},{"id":"d8ccd244-a4a8-4ec0-941e-feac5151c12a","slug":"cve-2026-92414","externalId":"CVE-2026-92414","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-92414 — : Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit.","description":": Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit.\n\n\n\nJackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with\n\nno credential check.\n\n\n\nThis issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17.\n\n\n\n\n\n\n\n\n\n\n\n\nUsers are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.","cveId":"CVE-2026-92414","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-384"],"tags":["nvd","status:received","status:undergoing-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/gmbsmrs2lycl9nld7rd0h1r1fc4t75qr","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/07/27","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.0062,"epssPercentile":0.48096,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:19:12.900Z","addedAt":"2026-10-07T16:39:32.788Z","updatedAt":"2026-10-08T18:39:30.530Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92414","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-92414","note":"authoritative record"}]},{"id":"e37643cf-6e98-425d-aaa8-60bcbf01fd9e","slug":"cve-2026-105233","externalId":"CVE-2026-105233","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105233 — A vulnerability has been found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79…","description":"A vulnerability has been found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file login.php of the component Login Flow. Such manipulation of the argument PHPSESSID leads to session fixiation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.","cveId":"CVE-2026-105233","cvssScore":2.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-384"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/kishor-23/food-waste-management-system/","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/kishor-23/food-waste-management-system/issues/16","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-105233","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/972904","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413433","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413433/cti","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00227,"epssPercentile":0.12351,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T06:16:57.803Z","addedAt":"2026-10-05T07:50:40.177Z","updatedAt":"2026-10-06T15:50:57.124Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105233","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105233","note":"authoritative record"}]},{"id":"255cef97-e991-4e57-a6e2-e9bec1aa46f4","slug":"cve-2026-104469","externalId":"CVE-2026-104469","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104469 — YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regene…","description":"YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session cookie can reuse it after login to access private content and perform actions with the victim's privileges.","cveId":"CVE-2026-104469","cvssScore":7.6,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-384"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-7fvc-v2hp-5pwh","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-session-fixation-via-login-in-authcontroller-php","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00233,"epssPercentile":0.13051,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:19.703Z","addedAt":"2026-10-02T13:50:40.719Z","updatedAt":"2026-10-06T17:50:41.585Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104469","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104469","note":"authoritative record"}]},{"id":"b09325ce-90ce-4185-a0dd-116cadf9f21d","slug":"cve-2026-102489","externalId":"CVE-2026-102489","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"Zammad GmbH Zammad Session Fixation Vulnerability","description":"Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework.","cveId":"CVE-2026-102489","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X","severity":"critical","vendor":"zammad","product":"zammad","affectedVersions":[">= 6.3.0, < 6.5.4",">= 7.0.0, <= 7.1.3",">= 6.3.0, <= 6.5.4"],"cwes":["CWE-384"],"tags":["nvd","status:received","status:deferred","status:undergoing-analysis","cisa-kev","known-exploited","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":true,"patchAvailable":true,"patchLinks":["https://zammad.com/en/product/releases/","https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-102489"],"references":[{"url":"https://csirt.divd.nl/CVE-2026-102489","type":"advisory","title":"Third Party Advisory"},{"url":"https://csirt.divd.nl/DIVD-2026-00015","type":"advisory","title":"Third Party Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-102489","type":"advisory","title":"US Government Resource"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","type":"advisory","title":"CISA Known Exploited Vulnerabilities Catalog"},{"url":"https://zammad.com/en/product/releases/","type":"other","title":"CISA catalog note"},{"url":"https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","type":"other","title":"CISA catalog note"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102489","type":"other","title":"CISA catalog note"},{"url":"https://zammad.com/en/advisories/cve-2026-102489-cve-2026-102490","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.01255,"epssPercentile":0.68609,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T17:16:40.550Z","addedAt":"2026-09-30T17:50:48.394Z","updatedAt":"2026-10-09T01:07:08.879Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102489","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102489","note":"authoritative record"}]},{"id":"828abb5d-62a8-40e8-a001-2354df9ca4fb","slug":"cve-2026-71302","externalId":"CVE-2026-71302","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-71302 — The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication.","description":"The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.","cveId":"CVE-2026-71302","cvssScore":7.5,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-384"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","type":"advisory","title":"ics-cert@hq.dhs.gov"}],"epssScore":0.00287,"epssPercentile":0.19443,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T22:18:18.817Z","addedAt":"2026-09-29T23:50:39.322Z","updatedAt":"2026-09-30T17:50:46.491Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71302","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-71302","note":"authoritative record"}]},{"id":"20d16b5b-0b61-4371-9389-39ca473c142f","slug":"cve-2026-101268","externalId":"CVE-2026-101268","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-101268 — If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account.","description":"If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. The attack only works when the event is available on a different domain than the organizer page.","cveId":"CVE-2026-101268","cvssScore":1.7,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-384"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://pretix.eu/about/en/blog/20260929-release-2026-7-1/","type":"advisory","title":"655498c3-6ec5-4f0b-aea6-853b334d05a6"}],"epssScore":0.00197,"epssPercentile":0.08578,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T13:17:49.597Z","addedAt":"2026-09-29T13:50:39.716Z","updatedAt":"2026-09-29T21:50:41.725Z","epssUpdatedAt":"2026-10-07T12:00:27.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101268","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-101268","note":"authoritative record"}]},{"id":"2d9c5ccb-fff3-4989-8b96-2acc400f2f5b","slug":"cve-2026-92609","externalId":"CVE-2026-92609","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-92609 — Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via r…","description":"Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication.\n\nThis issue affects Apache Qpid Broker-J: through 10.1.0.\n\nUsers are recommended to upgrade to version 10.1.1, which fixes the issue.","cveId":"CVE-2026-92609","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"apache","product":"qpid broker-j","affectedVersions":["< 10.1.1"],"cwes":["CWE-384"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/93w83oro48cqokb24k8tkogyvtlqhqw6","type":"vendor","title":"Vendor Advisory"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/24/17","type":"advisory","title":"Mailing List"}],"epssScore":0.00443,"epssPercentile":0.3649,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-25T08:16:41.203Z","addedAt":"2026-09-25T09:50:37.432Z","updatedAt":"2026-10-05T19:50:42.209Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92609","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-92609","note":"authoritative record"}]},{"id":"acfe8b86-c890-4f5b-b6ac-40361de9b44e","slug":"cve-2026-57179","externalId":"CVE-2026-57179","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-57179 — Python Social Auth is a social authentication/registration mechanism.","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session.","cveId":"CVE-2026-57179","cvssScore":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","severity":"medium","vendor":"PyPI","product":"social-auth-core","affectedVersions":["pkg:pypi/social-auth-core < 5.0.0"],"cwes":["CWE-384"],"tags":["nvd","status:received","osv","osv:ghsa-vqg6-3fw6-j9jg","ecosystem:pypi","status:awaiting-analysis","osv:pysec-2026-4168"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/python-social-auth/social-core/security/advisories/GHSA-vqg6-3fw6-j9jg","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-vqg6-3fw6-j9jg","type":"advisory","title":"OSV GHSA-vqg6-3fw6-j9jg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57179","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/python-social-auth/social-core/pull/1816","type":"other","title":"OSV web"},{"url":"https://github.com/python-social-auth/social-core/commit/0418782454ac7bbc6a9230ea21f7f5066fe89686","type":"other","title":"OSV web"},{"url":"https://github.com/python-social-auth/social-core","type":"vendor","title":"OSV package"},{"url":"https://github.com/python-social-auth/social-core/releases/tag/5.0.0","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4168","type":"advisory","title":"OSV PYSEC-2026-4168"},{"url":"https://pypi.org/project/social-auth-core","type":"vendor","title":"OSV package"},{"url":"https://github.com/advisories/GHSA-vqg6-3fw6-j9jg","type":"advisory","title":"OSV advisory"}],"epssScore":0.00158,"epssPercentile":0.04336,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T18:17:15.120Z","addedAt":"2026-09-24T19:50:39.308Z","updatedAt":"2026-10-01T19:54:36.156Z","epssUpdatedAt":"2026-10-07T12:00:27.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57179","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-57179","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-VQG6-3FW6-J9JG"}]},{"id":"9bef6842-88de-455c-bfea-148e48769c4b","slug":"cve-2026-95828","externalId":"CVE-2026-95828","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-95828 — A vulnerability was determined in Mstfakts College-Management-System.","description":"A vulnerability was determined in Mstfakts College-Management-System. This affects the function session_start of the file Front-end/server.php of the component Authentication. Executing a manipulation can lead to session fixiation. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.","cveId":"CVE-2026-95828","cvssScore":2.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-384"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Mstfakts/College-Management-System/","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/Mstfakts/College-Management-System/issues/8","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://vuldb.com/cve/CVE-2026-95828","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/897267","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/408521","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/408521/cti","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00486,"epssPercentile":0.39935,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T23:17:08.723Z","addedAt":"2026-09-22T23:50:37.525Z","updatedAt":"2026-09-23T15:50:39.628Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95828","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-95828","note":"authoritative record"}]},{"id":"c1e3216c-be4f-441e-b72d-0f4642936d56","slug":"cve-2026-79312","externalId":"CVE-2026-79312","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-79312 — webpy web.py 0.76 is vulnerable to Session Fixation.","description":"webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, and _save() writes back under the same session_id; no rotation after authentication, so a fixed session_id keeps the authenticated state.","cveId":"CVE-2026-79312","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-384"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79312.md","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/webpy/webpy","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00286,"epssPercentile":0.1934,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T16:17:56.630Z","addedAt":"2026-09-22T17:50:43.198Z","updatedAt":"2026-09-22T21:50:40.991Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79312","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-79312","note":"authoritative record"}]},{"id":"116dd16a-32bc-40ca-b298-de21a5393814","slug":"cve-2026-61687","externalId":"CVE-2026-61687","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-61687 — Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale.","description":"Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state parameter as equal, allowing an unauthenticated attacker to bind a victim's Hatchet session to an attacker-controlled OAuth identity. Exploitation requires the victim to have completed an OAuth flow in the current session and the deployment to enable auth.google.enabled, auth.github.enabled, or the Slack integration. This issue is fixed in version 0.91.1.","cveId":"CVE-2026-61687","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","severity":"high","vendor":"Go","product":"hatchet","affectedVersions":["pkg:golang/hatchet < 0.91.1","pkg:golang/github.com/hatchet-dev/hatchet","pkg:golang/github.com/hatchet-dev/hatchet < 0.91.2"],"cwes":["CWE-287","CWE-352","CWE-384","CWE-1275"],"tags":["nvd","status:received","osv","osv:ghsa-phg3-3g28-wq9v","ecosystem:go","status:deferred","osv:go-2026-6535"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/hatchet-dev/hatchet/commit/f90464189ad642251e09412d0f99fde353036428"],"references":[{"url":"https://github.com/hatchet-dev/hatchet/commit/f90464189ad642251e09412d0f99fde353036428","type":"patch","title":"OSV fix"},{"url":"https://github.com/hatchet-dev/hatchet/security/advisories/GHSA-phg3-3g28-wq9v","type":"advisory","title":"OSV advisory"},{"url":"https://osv.dev/vulnerability/GHSA-phg3-3g28-wq9v","type":"advisory","title":"OSV GHSA-phg3-3g28-wq9v"},{"url":"https://github.com/hatchet-dev/hatchet","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/GO-2026-6535","type":"advisory","title":"OSV GO-2026-6535"}],"epssScore":0.00171,"epssPercentile":0.05926,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-21T16:17:09.997Z","addedAt":"2026-09-21T17:50:42.271Z","updatedAt":"2026-10-07T18:42:44.256Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61687","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61687","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-PHG3-3G28-WQ9V"}]},{"id":"2584fbbc-7314-49a7-8739-56f93c421925","slug":"cve-2026-82355","externalId":"CVE-2026-82355","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-82355 — When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller fro…","description":"When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over cookie. The request then executes -- and is recorded in the audit log -- as the cookie's principal rather than the identity the client explicitly presented.\n\nOnly Apache Airflow 3.3.0 and 3.3.1 are affected. Earlier releases do not contain the code path that caches the cookie-derived user, and are not vulnerable.\n\nExploiting this requires an attacker to first place a valid session cookie of their own into the victim's browser or client: for example by cookie tossing from a sibling subdomain, through cross-site scripting in a separate application sharing a parent domain, or via a shared workstation. Deployments that host the Airflow UI on a domain shared with other applications are therefore the most exposed; a deployment on a dedicated domain with no co-hosted applications is not reachable this way. The consequence is principal confusion and misattributed audit records rather than a direct privilege escalation.\n\nUsers of 3.3.0 or 3.3.1 should upgrade to Apache Airflow 3.3.2 or later, which resolves the caller from the explicitly supplied credential whenever one is present.","cveId":"CVE-2026-82355","cvssScore":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","severity":"medium","vendor":"apache","product":"airflow","affectedVersions":["3.3.0","3.3.1","pkg:pypi/apache-airflow <= 3.3.0 || <= 3.3.1"],"cwes":["CWE-384"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","osv","osv:pysec-2026-3989","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/apache/airflow/pull/72225","https://github.com/apache/airflow/pull/72723"],"references":[{"url":"https://github.com/apache/airflow/pull/72225","type":"patch","title":"OSV fix"},{"url":"https://github.com/apache/airflow/pull/72723","type":"patch","title":"OSV fix"},{"url":"https://lists.apache.org/thread/3p7zpdvv40tn01m0xk5mt2rxg88mw8w1","type":"advisory","title":"OSV advisory"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/21/4","type":"advisory","title":"OSV advisory"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-3989","type":"advisory","title":"OSV PYSEC-2026-3989"}],"epssScore":0.00735,"epssPercentile":0.53029,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-21T15:17:32.430Z","addedAt":"2026-09-21T17:50:42.201Z","updatedAt":"2026-09-26T13:54:21.697Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82355","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-82355","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/PYSEC-2026-3989"}]},{"id":"3593c69f-06c2-4ee7-a8c2-f5c7aae30770","slug":"cve-2026-81181","externalId":"CVE-2026-81181","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-81181 — SysReptor is a fully customizable pentest reporting platform.","description":"SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation. An attacker who can obtain an unauthenticated SysReptor session cookie, place it in a victim's browser, and know the shared-note URL where the victim authenticates can reuse the fixed session after the victim enters the correct password and access that shared note. The main SysReptor login flow is not affected. This issue is fixed in version 2026.68.","cveId":"CVE-2026-81181","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-384"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Syslifters/sysreptor/commit/1981717f15afe945aa86d7e0dc9dc30a30c88dea","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Syslifters/sysreptor/releases/tag/2026.68","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Syslifters/sysreptor/security/advisories/GHSA-wgx3-84xg-q93j","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00279,"epssPercentile":0.18639,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-18T18:17:15.963Z","addedAt":"2026-09-18T19:50:41.688Z","updatedAt":"2026-09-21T21:50:37.770Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81181","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-81181","note":"authoritative record"}]},{"id":"fe534e15-6be0-4886-acc3-ad275f6e6c01","slug":"cve-2026-86688","externalId":"CVE-2026-86688","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86688 — Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to ho…","description":"Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in.\n\nAshAuthentication.Plug.Helpers.store_in_session/2 writes the authenticated subject into the existing session with Plug.Conn.put_session/3 and never calls Plug.Conn.configure_session(renew: true), so the identifier the visitor arrived with carries into their authenticated session. Every authentication event reaches this one function: the default success/4 injected by AshAuthentication.Phoenix.Controller.__using__/1, the AuthController emitted by mix ash_authentication_phoenix.install, and remember-me auto-login. AshAuthentication.Phoenix.Plug.store_in_session/2 is a defdelegate to it. Logout does not close the window either, because clear_session/2 ends with Plug.Conn.clear_session/1, which clears session contents but leaves the identifier intact, so a planted identifier survives a logout-then-login cycle.\n\nThis issue affects ash_authentication: from 0.2.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.","cveId":"CVE-2026-86688","cvssScore":7.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-384"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cna.erlef.org/cves/CVE-2026-86688.html","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/team-alembic/ash_authentication/commit/3e1d452cbf1564e87f5f97be882b66fe25af7cfa","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/team-alembic/ash_authentication/commit/872db454405ecad4fcdabd9ff3d8755d1d6a69ae","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/team-alembic/ash_authentication/commit/a939dde9b917c072cdf10c4b0913a9886a4b0231","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-v577-944g-7h3x","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-86688","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"}],"epssScore":0.00742,"epssPercentile":0.5326,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T22:17:04.180Z","addedAt":"2026-09-17T23:50:35.803Z","updatedAt":"2026-09-18T19:50:40.414Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86688","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86688","note":"authoritative record"}]},{"id":"49ae770a-8a3f-4496-b10a-7e2798a79d12","slug":"cve-2026-92984","externalId":"CVE-2026-92984","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-92984 — HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated …","description":"HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send victims a crafted link containing it, and replay the identifier after the victim authenticates to hijack their account and access.","cveId":"CVE-2026-92984","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-384"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/hubzero/hubzero-cms","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/hubzero/hubzero-cms/blob/v2.2.32/core/libraries/Hubzero/Session/Manager.php#L123-L132","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/hubzero/hubzero-cms/commit/e60e8ebee5e1d38b1db1fc41bd9164b265b24356","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hubzero-cms-through-2.2.32-session-fixation-via-query-string-session-identifier","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00464,"epssPercentile":0.3819,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T15:17:01.690Z","addedAt":"2026-09-17T15:50:39.341Z","updatedAt":"2026-09-22T21:50:39.863Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92984","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-92984","note":"authoritative record"}]},{"id":"ac5b9777-d9a5-4ee4-9328-0080ad20ad2c","slug":"cve-2026-77614","externalId":"CVE-2026-77614","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-77614 — Opencast is a free, open-source platform to support the management of educational audio and video content.","description":"Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected JSESSIONID from the ;jsessionid= URL path parameter and does not replace it when the victim logs in. An unauthenticated attacker can send a crafted link to a victim whose browser has no active Opencast session cookie, wait for the victim to authenticate, and then reuse the known identifier as the victim's authenticated session. This can expose the victim's data and actions and can produce full administrative account takeover when the victim is an administrator. This issue is fixed in versions 19.7 and 20.2.","cveId":"CVE-2026-77614","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-384"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/opencast/opencast/commit/c36652250a026afb7cf78b663950c702669f1d3f","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/opencast/opencast/commit/ff84128c9b3bcbd79c28192d25929dab8faf185f","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/opencast/opencast/releases/tag/19.7","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/opencast/opencast/releases/tag/20.2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/opencast/opencast/security/advisories/GHSA-6f53-jp7x-gg7p","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00549,"epssPercentile":0.44239,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T15:16:51.503Z","addedAt":"2026-09-17T15:50:39.262Z","updatedAt":"2026-09-30T19:50:41.930Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77614","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-77614","note":"authoritative record"}]},{"id":"1cad58f4-abef-45fb-bb6f-3f32d0d9885d","slug":"cve-2026-78428","externalId":"CVE-2026-78428","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-78428 — For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated ses…","description":"For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently","cveId":"CVE-2026-78428","cvssScore":8.8,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-384"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1279937","type":"advisory","title":"meissner@suse.de"},{"url":"https://github.com/neuvector/neuvector/security/advisories/GHSA-c6rx-pmvf-m3jx","type":"advisory","title":"meissner@suse.de"}],"epssScore":0.00267,"epssPercentile":0.17297,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T10:17:03.760Z","addedAt":"2026-09-17T11:50:35.755Z","updatedAt":"2026-09-28T13:50:40.685Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78428","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-78428","note":"authoritative record"}]},{"id":"c629e2d2-6184-4ab9-82e7-8dd6e0c31a49","slug":"cve-2026-61592","externalId":"CVE-2026-61592","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-61592 — djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance.","description":"djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the victim's identity and state. This is fixed in djust 1.0.7. Each SSE session is bound to its owning principal at creation and cross-principal access is rejected; SSE session creation is additionally capped per principal. As a workaround, disable the SSE transport.","cveId":"CVE-2026-61592","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":"PyPI","product":"djust","affectedVersions":["pkg:pypi/djust < 1.0.7"],"cwes":["CWE-384","CWE-639","CWE-862"],"tags":["nvd","status:received","osv","osv:ghsa-f795-p5jw-j6g2","ecosystem:pypi","status:deferred","osv:pysec-2026-4043"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/djust-org/djust/releases/tag/v1.0.7","type":"other","title":"OSV web"},{"url":"https://github.com/djust-org/djust/security/advisories/GHSA-f795-p5jw-j6g2","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-f795-p5jw-j6g2","type":"advisory","title":"OSV GHSA-f795-p5jw-j6g2"},{"url":"https://github.com/djust-org/djust","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4043","type":"advisory","title":"OSV PYSEC-2026-4043"},{"url":"https://pypi.org/project/djust","type":"vendor","title":"OSV package"},{"url":"https://github.com/advisories/GHSA-f795-p5jw-j6g2","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61592","type":"advisory","title":"OSV advisory"}],"epssScore":0.00388,"epssPercentile":0.30731,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T22:17:02.900Z","addedAt":"2026-09-16T23:50:35.514Z","updatedAt":"2026-10-01T19:54:36.852Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61592","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61592","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-F795-P5JW-J6G2"}]}],"pagination":{"page":1,"limit":20,"total":51,"totalPages":3,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:16:57.015Z","durationMs":106,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-384"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}