{"success":true,"data":{"threats":[{"id":"57eb179a-6e66-40a5-add9-291967e26a1e","slug":"cve-2026-107392","externalId":"CVE-2026-107392","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107392 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. Prior to 11.15.0, the DSF parser handles an unrecognized chunk by calling tokenizer.ignore without awaiting the returned promise and without first rejecting a chunk size smaller than the 12-byte chunk header. A crafted DSF input can produce a negative ignore length; with strtok3 10.3.5 or later, the resulting RangeError is detached from the parseBuffer promise and becomes an unhandled rejection under Node.js default behavior. The parse call can appear to resolve before the process crashes, bypassing per-parse try/catch handling. The demonstrated impact is availability loss only and requires the DSF parsing path. This issue is fixed in version 11.15.0.","cveId":"CVE-2026-107392","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.15.0"],"cwes":["CWE-248","CWE-400"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-8j4c-6x6g-rq3j","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/e7fc27a96e789d41ece41fdac590fc7618274a41","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2700","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.15.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-8j4c-6x6g-rq3j","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-8j4c-6x6g-rq3j","type":"advisory","title":"OSV GHSA-8j4c-6x6g-rq3j"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:33.707Z","addedAt":"2026-10-08T21:05:52.984Z","updatedAt":"2026-10-08T21:08:30.817Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107392","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107392","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-8J4C-6X6G-RQ3J"}]},{"id":"058f0d42-6c83-46b2-ac64-ab25a6feb0d3","slug":"cve-2026-107391","externalId":"CVE-2026-107391","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107391 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. In the public development revision introduced after 11.14.0, a development-branch regression in the MP4 stsd sample-description parser allows an attacker-controlled sample-entry size of zero to prevent the StsdAtom.get cursor from advancing while an attacker-controlled entry_count keeps the synchronous loop running. A crafted MP4-family input can block the Node.js event loop and grow the sample-description table until the process is terminated or exhausts memory. The vulnerable change was present on the public master branch but was not included in music-metadata 11.14.0 or any earlier npm release, and version 11.16.0 contains the fix. This issue is fixed in version 11.16.0.","cveId":"CVE-2026-107391","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.16.0"],"cwes":["CWE-400","CWE-835"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-f94x-6692-553q","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/90a7d52c69e921a0b019592d887acd97b1c8b8a5","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2734","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.16.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-f94x-6692-553q","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-f94x-6692-553q","type":"advisory","title":"OSV GHSA-f94x-6692-553q"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:33.530Z","addedAt":"2026-10-08T21:05:52.968Z","updatedAt":"2026-10-08T21:08:30.734Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107391","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107391","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-F94X-6692-553Q"}]},{"id":"764e6a60-ef12-4537-9496-e9804976699e","slug":"cve-2026-95209","externalId":"CVE-2026-95209","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-95209 — An issue in gnutls v3.8.13 causes legitimate CA certificates to be rejected, leading to a Denial of Service (DoS).","description":"An issue in gnutls v3.8.13 causes legitimate CA certificates to be rejected, leading to a Denial of Service (DoS).","cveId":"CVE-2026-95209","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"http://gnutls.com/","type":"advisory","title":"cve@mitre.org"},{"url":"https://evil.com/","type":"advisory","title":"cve@mitre.org"},{"url":"https://gist.github.com/lkloliver/8e4498311aff18e2077010e412043e18","type":"advisory","title":"cve@mitre.org"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:20:52.830Z","addedAt":"2026-10-08T19:33:17.171Z","updatedAt":"2026-10-08T23:06:39.224Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95209","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-95209","note":"authoritative record"}]},{"id":"cfd6acce-297e-4795-b26a-b09096f250c6","slug":"cve-2026-84276","externalId":"CVE-2026-84276","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84276 — IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller.","description":"IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that triggers an unchecked type assertion, causing the edge-controller process to terminate unexpectedly.","cveId":"CVE-2026-84276","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288627","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:20:51.240Z","addedAt":"2026-10-08T19:33:17.118Z","updatedAt":"2026-10-08T21:05:52.634Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84276","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84276","note":"authoritative record"}]},{"id":"fa645e2f-f5d3-49fe-861f-55b0bcd94afb","slug":"cve-2026-95184","externalId":"CVE-2026-95184","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-95184 — Improper certificate validation in gnutls v3.8.13 causes the application to reject legitimate certificates for valid users, leading to a Denial of …","description":"Improper certificate validation in gnutls v3.8.13 causes the application to reject legitimate certificates for valid users, leading to a Denial of Service (DoS).","cveId":"CVE-2026-95184","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"http://gnutls.com/","type":"advisory","title":"cve@mitre.org"},{"url":"https://evil.com/","type":"advisory","title":"cve@mitre.org"},{"url":"https://gist.github.com/lkloliver/0c8b47fa75a0958fa88587665b82ae15","type":"advisory","title":"cve@mitre.org"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:18:33.240Z","addedAt":"2026-10-08T18:39:31.984Z","updatedAt":"2026-10-08T23:06:39.036Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95184","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-95184","note":"authoritative record"}]},{"id":"d6bbe1a7-c8fe-4f7a-a8a2-6d7b4396c996","slug":"ghsa-rp9v-7xv3-r6g3","externalId":"GHSA-rp9v-7xv3-r6g3","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Coraza: Resource exhaustion via deferred file handle accumulation in multipart body processor","description":"## Summary\n\n`defer temp.Close()` sits inside a `for` loop in the multipart processor. Go defers run at function return, not loop end, so every file part in the request holds an open fd until `ProcessRequest()` exits. Send enough parts and you hit `EMFILE`. With CRS loaded, that flips `MULTIPART_STRICT_ERROR` to 1 and rule `200001` starts returning 400s, including on legitimate requests hitting the same condition.\n\n## Details\n\n`internal/bodyprocessors/multipart.go`, line 69:\n\n```go\nfor {\n    p, err := mr.NextPart()\n    // ...\n    temp, err := os.CreateTemp(storagePath, \"crzmp*\")\n    defer temp.Close() // wrong scope\n    io.Copy(temp, p)\n}\n```\n\nEach iteration opens a temp file and defers its close. All of them stack up and fire together when `ProcessRequest` returns. 500 parts, 500 fds held simultaneously.\n\nThe body size limit (default 128MB) caps total bytes, not part count. A minimal file part (boundary line, `Content-Disposition` with `filename=`, one byte of content) is about 104 bytes. That's roughly 65,000 parts per 6.8MB of body, which on a standard Linux system (hard fd limit 65536) is enough to exhaust the table.\n\nFix is straightforward: call `temp.Close()` explicitly after `io.Copy` instead of deferring it.\n\n## PoC\n\nTested on v3.7.0 (`db9850b`), Go 1.25, Linux x86_64.\n\nAdd this file at `internal/bodyprocessors/poc_fd_test.go` and run:\n\n```text\ngo test -v -run TestMultipartFDLeak ./internal/bodyprocessors/...\n```\n\n```go\npackage bodyprocessors_test\n\nimport (\n\t\"fmt\"\n\t\"os\"\n\t\"strings\"\n\t\"sync\"\n\t\"sync/atomic\"\n\t\"testing\"\n\n\t\"github.com/corazawaf/coraza/v3/experimental/plugins/plugintypes\"\n\t\"github.com/corazawaf/coraza/v3/internal/bodyprocessors\"\n\t\"github.com/corazawaf/coraza/v3/internal/corazawaf\"\n)\n\nfunc countFDs() int {\n\te, _ := os.ReadDir(\"/proc/self/fd\")\n\treturn len(e)\n}\n\nfunc TestMultipartFDLeak(t *testing.T) {\n\tboundary := \"testboundary\"\n\tvar sb strings.Builder\n\tfor i := 0; i < 500; i++ {\n\t\tfmt.Fprintf(&sb, \"--%s\\r\\n\", boundary)\n\t\tfmt.Fprintf(&sb, \"Content-Disposition: form-data; name=\\\"f%d\\\"; filename=\\\"f%d.txt\\\"\\r\\n\", i, i)\n\t\tsb.WriteString(\"\\r\\n\")\n\t\tsb.WriteString(\"X\\r\\n\")\n\t}\n\tfmt.Fprintf(&sb, \"--%s--\\r\\n\", boundary)\n\n\tmp, _ := bodyprocessors.GetBodyProcessor(\"multipart\")\n\tbaseline := countFDs()\n\n\tvar peak int64\n\tdone := make(chan struct{})\n\tvar wg sync.WaitGroup\n\twg.Add(1)\n\tgo func() {\n\t\tdefer wg.Done()\n\t\tfor {\n\t\t\tselect {\n\t\t\tcase <-done:\n\t\t\t\treturn\n\t\t\tdefault:\n\t\t\t\tn := int64(countFDs())\n\t\t\t\tfor {\n\t\t\t\t\tcur := atomic.LoadInt64(&peak)\n\t\t\t\t\tif n <= cur || atomic.CompareAndSwapInt64(&peak, cur, n) {\n\t\t\t\t\t\tbreak\n\t\t\t\t\t}\n\t\t\t\t}\n\t\t\t}\n\t\t}\n\t}()\n\n\tv := corazawaf.NewTransactionVariables()\n\tmp.ProcessRequest(strings.NewReader(sb.String()), v,\n\t\tplugintypes.BodyProcessorOptions{\n\t\t\tMime:        \"multipart/form-data; boundary=\" + boundary,\n\t\t\tStoragePath: t.TempDir(),\n\t\t})\n\tclose(done)\n\twg.Wait()\n\n\tt.Logf(\"baseline=%d  peak=%d  spike=+%d\",\n\t\tbaseline, atomic.LoadInt64(&peak),\n\t\tatomic.LoadInt64(&peak)-int64(baseline))\n}\n```\n\nOutput:\n\n```text\nbaseline=7  peak=506  spike=+499\n```\n\nThe spike is ~1 fd per part. After `ProcessRequest` returns the deferred closes fire and it drops back to baseline.\n\n## Impact\n\n- **No authentication required.** Any endpoint that accepts multipart uploads is affected.\n- **fd exhaustion at ~6.8MB body (~65k parts).** `os.CreateTemp` starts returning errors and `MULTIPART_STRICT_ERROR` is set to 1.\n- **CRS false positives / DoS.** With CRS loaded, rule `200001` then blocks the request with a 400 — and any other multipart request processed concurrently that runs into the same condition gets blocked too. At that point the WAF can't distinguish the attack from a legitimate upload.\n- **Process-wide impact.** While the fd table is full the process can't open sockets or files for anything else either.\n- **Scope.** Affects all v3.x releases; the `defer` has been present since the multipart processor was introduced.","cveId":null,"cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":"Go","product":"github.com/corazawaf/coraza/v3","affectedVersions":["pkg:golang/github.com/corazawaf/coraza/v3 >= 3.0.0, < 3.8.0"],"cwes":["CWE-400","CWE-772"],"tags":["osv","osv:ghsa-rp9v-7xv3-r6g3","ecosystem:go"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-rp9v-7xv3-r6g3","type":"advisory","title":"OSV GHSA-rp9v-7xv3-r6g3"},{"url":"https://github.com/corazawaf/coraza/security/advisories/GHSA-rp9v-7xv3-r6g3","type":"other","title":"OSV web"},{"url":"https://github.com/corazawaf/coraza/commit/1bc39036e99c88e7de60cf8e6bb55ee4c311223c","type":"other","title":"OSV web"},{"url":"https://github.com/corazawaf/coraza","type":"vendor","title":"OSV package"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.8.0","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:52:00.000Z","addedAt":"2026-10-08T18:42:41.912Z","updatedAt":"2026-10-08T18:42:41.912Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-rp9v-7xv3-r6g3"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-rp9v-7xv3-r6g3"}]},{"id":"21e076b8-5848-4024-bfa6-6db4d33912be","slug":"cve-2026-61801","externalId":"CVE-2026-61801","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-61801 — The `github.com/moby/sys/user` package provides Go utilities for parsing and looking up entries in Unix-style user and group database files.","description":"The `github.com/moby/sys/user` package provides Go utilities for parsing and looking up entries in Unix-style user and group database files. Versions before 0.4.1 do not sufficiently limit entries when parsing `/etc/passwd`- or `/etc/group`-style files, allowing an attacker who can supply a specially crafted file to cause excessive memory consumption and potentially terminate the affected process due to an out-of-memory condition. This issue is patched in version 0.4.1. As a workaround, avoid parsing attacker-controlled user or group database files, or validate and limit untrusted input before parsing it.","cveId":"CVE-2026-61801","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"Go","product":"github.com/moby/sys/user","affectedVersions":["pkg:golang/github.com/moby/sys/user < 0.4.1"],"cwes":["CWE-400"],"tags":["nvd","status:received","osv","osv:ghsa-mjcv-p78q-w5fw","ecosystem:go","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/moby/sys/commit/85a71bbe1faa36c552a960e6a5f3d0cfb632fbbe","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/moby/sys/pull/221","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/moby/sys/security/advisories/GHSA-mjcv-p78q-w5fw","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-mjcv-p78q-w5fw","type":"advisory","title":"OSV GHSA-mjcv-p78q-w5fw"},{"url":"https://github.com/moby/sys","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:17.433Z","addedAt":"2026-10-08T18:39:31.796Z","updatedAt":"2026-10-08T23:06:38.597Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61801","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61801","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-MJCV-P78Q-W5FW"}]},{"id":"651ee712-8c63-46c7-98c1-eea19f720dea","slug":"cve-2026-107294","externalId":"CVE-2026-107294","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107294 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.","description":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.2 and 2.24.0, web_fetch_tool, the WebFetch local fallback, and remote FileUrl media downloads buffer the complete HTTP response body before enforcing content-size controls. An attacker-influenced URL can stream an arbitrarily large response that exhausts process memory and crashes the worker; affected media types include ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. SSRF protections remain effective, and the impact is limited to availability. This issue is fixed in versions 1.107.2 and 2.24.0.","cveId":"CVE-2026-107294","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"PyPI","product":"pydantic-ai","affectedVersions":["pkg:pypi/pydantic-ai >= 1.77.0, < 1.107.2","pkg:pypi/pydantic-ai >= 2.0.0b1, < 2.24.0","pkg:pypi/pydantic-ai-slim >= 1.77.0, < 1.107.2","pkg:pypi/pydantic-ai-slim >= 2.0.0b1, < 2.24.0"],"cwes":["CWE-400","CWE-770"],"tags":["nvd","status:received","osv","osv:ghsa-v2xh-2vp8-57h8","ecosystem:pypi","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/7a64d049c3f5271a975cd1d64b2fa876d83ede1d","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/e3824a58c82864ed26afb2887619834a4eb86cc8","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/7141","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/7308","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.24.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-v2xh-2vp8-57h8","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-v2xh-2vp8-57h8","type":"advisory","title":"OSV GHSA-v2xh-2vp8-57h8"},{"url":"https://github.com/pydantic/pydantic-ai","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:15.080Z","addedAt":"2026-10-08T18:39:31.708Z","updatedAt":"2026-10-08T21:05:51.146Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107294","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107294","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-V2XH-2VP8-57H8"}]},{"id":"e946f2a2-ea10-4793-b171-446d79612075","slug":"cve-2026-107287","externalId":"CVE-2026-107287","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107287 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.","description":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.7 and 2.52.0, the local web_fetch_tool and the WebFetch local fallback can consume excessive CPU and memory during HTML-to-Markdown conversion of attacker-controlled HTML containing deeply nested block elements. Conversion repeatedly reprocesses accumulated text and can greatly expand intermediate output before the returned-content limit is applied, allowing a model-directed fetch to delay other work in the process. Provider-native web fetching is not affected. This issue is fixed in versions 1.107.7 and 2.52.0.","cveId":"CVE-2026-107287","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":"PyPI","product":"pydantic-ai","affectedVersions":["pkg:pypi/pydantic-ai >= 1.77.0, < 1.107.7","pkg:pypi/pydantic-ai >= 2.0.0b1, < 2.52.0","pkg:pypi/pydantic-ai-slim >= 1.77.0, < 1.107.7","pkg:pypi/pydantic-ai-slim >= 2.0.0b1, < 2.52.0"],"cwes":["CWE-400","CWE-407"],"tags":["nvd","status:received","osv","osv:ghsa-v36g-jcw9-x7cw","ecosystem:pypi","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/2b247add4950bef61d352e7ca8aefbd20539180c","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/2fd38792693da00a3ca5412aeffb436787af3545","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8984","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8985","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.7","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.52.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-v36g-jcw9-x7cw","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-v36g-jcw9-x7cw","type":"advisory","title":"OSV GHSA-v36g-jcw9-x7cw"},{"url":"https://github.com/pydantic/pydantic-ai","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:17:03.973Z","addedAt":"2026-10-08T16:39:36.009Z","updatedAt":"2026-10-08T23:06:38.388Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107287","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107287","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-V36G-JCW9-X7CW"}]},{"id":"e494786a-7286-4494-ace0-160e335c2a04","slug":"cve-2026-14509","externalId":"CVE-2026-14509","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-14509 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a re…","description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to algorithmic complexity in linked-list traversal.","cveId":"CVE-2026-14509","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7289775","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:49.560Z","addedAt":"2026-10-08T16:39:35.928Z","updatedAt":"2026-10-08T21:05:50.459Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14509","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-14509","note":"authoritative record"}]},{"id":"1511c6cb-3929-4849-b270-6d5f657eb9bb","slug":"cve-2026-105830","externalId":"CVE-2026-105830","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105830 — league/commonmark from 2.0.0 before 2.10.2 contains a quadratic-time denial of service vulnerability in the GitHub Flavored Markdown Table extensio…","description":"league/commonmark from 2.0.0 before 2.10.2 contains a quadratic-time denial of service vulnerability in the GitHub Flavored Markdown Table extension's TableStartParser::tryStart() block-start scan. Unauthenticated attackers can submit a large paragraph of pipe-free lines not starting with letters, forcing repeated full-buffer strpos scans that exhaust PHP worker CPU.","cveId":"CVE-2026-105830","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/thephpleague/commonmark/security/advisories/GHSA-3q6v-r5mr-hxv8","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.vulncheck.com/advisories/league-commonmark-2.0.0-before-2.10.2-quadratic-dos-via-tablestartparser","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:35.340Z","addedAt":"2026-10-08T16:39:35.703Z","updatedAt":"2026-10-08T23:06:38.195Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105830","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105830","note":"authoritative record"}]},{"id":"163b5b0c-d597-42d1-9bd8-dfb9fb4cba80","slug":"cve-2026-105825","externalId":"CVE-2026-105825","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105825 — ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a denial of service vulnerability in its handling of XMP profiles, where a crafted pr…","description":"ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a denial of service vulnerability in its handling of XMP profiles, where a crafted profile terminates the process instead of raising an exception. Attackers can supply images with malicious XMP profiles to crash applications that process them using ImageMagick.","cveId":"CVE-2026-105825","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-27m9-54jx-fgvq","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-via-crafted-xmp-profile","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:34.490Z","addedAt":"2026-10-08T16:39:35.665Z","updatedAt":"2026-10-08T21:05:49.935Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105825","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105825","note":"authoritative record"}]},{"id":"8edb01b0-3586-440f-b167-cf6e99abe202","slug":"cve-2026-105402","externalId":"CVE-2026-105402","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105402 — ImageMagick before 7.1.2-31 contains a denial of service vulnerability that allows attackers to disrupt processing by supplying a crafted XMP profile.","description":"ImageMagick before 7.1.2-31 contains a denial of service vulnerability that allows attackers to disrupt processing by supplying a crafted XMP profile. Attackers can embed a malicious XMP profile that triggers a failure when determining the numerator and denominator, crashing or hanging image processing.","cveId":"CVE-2026-105402","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v45j-x8p4-3mh4","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-denial-of-service-via-xmp-profile-parsing","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:33.473Z","addedAt":"2026-10-08T16:39:35.621Z","updatedAt":"2026-10-08T21:05:49.725Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105402","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105402","note":"authoritative record"}]},{"id":"67a9327f-a976-412a-aa62-bb3a4f76b264","slug":"cve-2026-105399","externalId":"CVE-2026-105399","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105399 — ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder caused by a missing limit check.","description":"ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder caused by a missing limit check. Attackers can supply a crafted MVG image that triggers a long-running decoding operation, consuming excessive CPU resources and stalling image processing.","cveId":"CVE-2026-105399","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qr53-hc3p-fc62","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-denial-of-service-via-mvg-decoder","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:32.960Z","addedAt":"2026-10-08T16:39:35.599Z","updatedAt":"2026-10-08T21:05:49.665Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105399","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105399","note":"authoritative record"}]},{"id":"88f247b4-db33-4554-89a4-2d19869646a6","slug":"cve-2026-16169","externalId":"CVE-2026-16169","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-16169 — IBM DataPower Gateway 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.","description":"IBM DataPower Gateway 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.","cveId":"CVE-2026-16169","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7289798","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:15.520Z","addedAt":"2026-10-08T14:40:02.594Z","updatedAt":"2026-10-08T21:05:48.744Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16169","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-16169","note":"authoritative record"}]},{"id":"48280bc4-ead1-4632-9e67-1a1d53ec877a","slug":"cve-2026-107227","externalId":"CVE-2026-107227","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107227 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSize do not bound decompressed output. A malicious WebSocket peer can send a small compressed message that expands to a very large Netty buffer and exhausts JVM heap. This issue is fixed in version 3.0.14.","cveId":"CVE-2026-107227","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.14","pkg:maven/org.asynchttpclient/async-http-client >= 2.2.0, <= 2.16.1"],"cwes":["CWE-400","CWE-409"],"tags":["nvd","status:received","osv","osv:ghsa-x8v2-478q-2hvg","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-x8v2-478q-2hvg","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-x8v2-478q-2hvg","type":"advisory","title":"OSV GHSA-x8v2-478q-2hvg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107227","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00432,"epssPercentile":0.35395,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T21:17:14.283Z","addedAt":"2026-10-07T22:39:36.526Z","updatedAt":"2026-10-08T21:05:43.928Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107227","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107227","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-X8V2-478Q-2HVG"}]},{"id":"aa25e641-61b4-469f-bf6f-3d772f25dc0a","slug":"cve-2026-97717","externalId":"CVE-2026-97717","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97717 — CVE-2026-97717\nis a vulnerability in the proxy sub-system of Secure Access servers prior to\n14.60.","description":"CVE-2026-97717\nis a vulnerability in the proxy sub-system of Secure Access servers prior to\n14.60. Authenticated attackers can send malformed data to the server and cause\na persistent denial of service.","cveId":"CVE-2026-97717","cvssScore":6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-97717---6-0-medium","type":"advisory","title":"SecurityResponse@netmotionsoftware.com"}],"epssScore":0.00226,"epssPercentile":0.12195,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T20:17:16.347Z","addedAt":"2026-10-07T20:39:40.512Z","updatedAt":"2026-10-08T23:06:36.893Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97717","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97717","note":"authoritative record"}]},{"id":"2d9be6b2-de5b-4e98-998b-3a2421ef5a66","slug":"cve-2026-97716","externalId":"CVE-2026-97716","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97716 — CVE-2026-97716\nis a vulnerability in the connection set up sub-system of Secure Access servers\nprior to version 14.60.","description":"CVE-2026-97716\nis a vulnerability in the connection set up sub-system of Secure Access servers\nprior to version 14.60. Unauthenticated attackers can send specially crafted\ntraffic to the server and cause a persistent denial of service.","cveId":"CVE-2026-97716","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-97716---8-7-high","type":"advisory","title":"SecurityResponse@netmotionsoftware.com"}],"epssScore":0.00344,"epssPercentile":0.25802,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T20:17:16.193Z","addedAt":"2026-10-07T20:39:40.505Z","updatedAt":"2026-10-08T23:06:36.878Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97716","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97716","note":"authoritative record"}]},{"id":"63d2ec82-4e99-4dbe-925e-e7fb7395e53f","slug":"cve-2026-97715","externalId":"CVE-2026-97715","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97715 — CVE-2026-97715 is\na vulnerability in the client registration process of Secure Access servers\nprior to version 14.60.","description":"CVE-2026-97715 is\na vulnerability in the client registration process of Secure Access servers\nprior to version 14.60. Authenticated attackers can pass malformed data to the\nserver and cause a persistent denial of service.","cveId":"CVE-2026-97715","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-97715---7-1-high","type":"advisory","title":"SecurityResponse@netmotionsoftware.com"}],"epssScore":0.00226,"epssPercentile":0.12195,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T20:17:16.053Z","addedAt":"2026-10-07T20:39:40.498Z","updatedAt":"2026-10-08T23:06:36.862Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97715","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97715","note":"authoritative record"}]},{"id":"1da90731-0bc6-4519-8f34-ca027f85dbec","slug":"cve-2026-97714","externalId":"CVE-2026-97714","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97714 — CVE-2026-97714\nis a is a vulnerability in the authentication sub-system of Secure Access\nservers prior to version 14.60.","description":"CVE-2026-97714\nis a is a vulnerability in the authentication sub-system of Secure Access\nservers prior to version 14.60. Attackers can send a malformed response during\nauthentication and cause a persistent denial of service.","cveId":"CVE-2026-97714","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-97714---8-2-high","type":"advisory","title":"SecurityResponse@netmotionsoftware.com"}],"epssScore":0.00252,"epssPercentile":0.15346,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T20:17:15.893Z","addedAt":"2026-10-07T20:39:40.491Z","updatedAt":"2026-10-08T23:06:36.827Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97714","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97714","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":1093,"totalPages":55,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:44:27.204Z","durationMs":55,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-400"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}