{"success":true,"data":{"threats":[{"id":"93ee4c14-2fae-4123-89b4-a35e42c2668f","slug":"cve-2026-107378","externalId":"CVE-2026-107378","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107378 — CairoSVG is an SVG converter based on Cairo, a 2D graphics library.","description":"CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in cairosvg/path.py. The path tokenizer repeatedly slices and rescans the remaining path data, while draw_markers drains node.vertices with node.vertices.pop(0), causing repeated linear-time work. The svg2png, svg2pdf, and svg2ps APIs reach these operations during ordinary rendering, allowing a sub-megabyte SVG to consume substantial CPU and deny service to a rendering application. This issue is fixed in version 2.9.1.","cveId":"CVE-2026-107378","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"PyPI","product":"cairosvg","affectedVersions":["pkg:pypi/cairosvg < 2.9.1"],"cwes":["CWE-407"],"tags":["nvd","status:received","osv","osv:ghsa-c3jg-qh8m-j3h2","ecosystem:pypi","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Kozea/CairoSVG/commit/9d63f049f9988d0ddda3eb94564ac3a50a286523","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Kozea/CairoSVG/commit/a4d585eb374724b79676e9cceaa9e9a1a4358565","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Kozea/CairoSVG/releases/tag/2.9.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/Kozea/CairoSVG/security/advisories/GHSA-c3jg-qh8m-j3h2","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-c3jg-qh8m-j3h2","type":"advisory","title":"OSV GHSA-c3jg-qh8m-j3h2"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107378","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/Kozea/CairoSVG","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:23.417Z","addedAt":"2026-10-08T18:39:31.903Z","updatedAt":"2026-10-08T23:06:38.820Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107378","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107378","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-C3JG-QH8M-J3H2"}]},{"id":"73c988d9-ad13-4046-8491-58f80a4b1744","slug":"cve-2026-107297","externalId":"CVE-2026-107297","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107297 — msgpack5 is a msgpack v5 implementation for node.js and the browser.","description":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elements to be decoded repeatedly, producing quadratic CPU use and blocking the event loop. This issue is fixed in version 6.1.0.","cveId":"CVE-2026-107297","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"msgpack5","affectedVersions":["pkg:npm/msgpack5 < 6.1.0"],"cwes":["CWE-407"],"tags":["nvd","status:received","osv","osv:ghsa-gcx5-hxj7-gpqq","ecosystem:npm","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mcollina/msgpack5/commit/e4827641d3105e295cbbd56e9c5389978547eab4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-gcx5-hxj7-gpqq","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-gcx5-hxj7-gpqq","type":"advisory","title":"OSV GHSA-gcx5-hxj7-gpqq"},{"url":"https://github.com/mcollina/msgpack5","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:15.550Z","addedAt":"2026-10-08T18:39:31.730Z","updatedAt":"2026-10-08T21:05:51.280Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107297","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107297","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-GCX5-HXJ7-GPQQ"}]},{"id":"da086cbd-a4e3-4bff-bbca-f6a47963456c","slug":"cve-2026-107290","externalId":"CVE-2026-107290","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107290 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.","description":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback process server-controlled responses with quadratic title extraction, whitespace normalization, and ordered-list numbering. An attacker-controlled page of modest size can therefore block the event loop for an extended period, stalling other agent runs and requests, while unsupported codecs or excessive HTML or JSON nesting can abort an individual run. This issue is fixed in versions 1.107.6 and 2.44.0.","cveId":"CVE-2026-107290","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"PyPI","product":"pydantic-ai","affectedVersions":["pkg:pypi/pydantic-ai >= 1.77.0, < 1.107.6","pkg:pypi/pydantic-ai >= 2.0.0b1, < 2.44.0","pkg:pypi/pydantic-ai-slim >= 1.77.0, < 1.107.6","pkg:pypi/pydantic-ai-slim >= 2.0.0b1, < 2.44.0"],"cwes":["CWE-1333","CWE-407"],"tags":["nvd","status:received","osv","osv:ghsa-fpf4-vwcp-v4hp","ecosystem:pypi","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/2faa6181d8a17d83bc9516d035c5270db8730fa0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/9cdc952e4c3319e85a3e04f2de49fbbb765bd38b","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/a93ea5226be1e93ae13131ae3f22287190411389","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/c3fd1cc1f15fdbf750d78e4e3ec1e8b4d6a3d920","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/fb92ccfc3ca2735dab877e2ed73856681bf72ad1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8397","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8399","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8418","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/84332","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8434","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-fpf4-vwcp-v4hp","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-fpf4-vwcp-v4hp","type":"advisory","title":"OSV GHSA-fpf4-vwcp-v4hp"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8433","type":"other","title":"OSV web"},{"url":"https://github.com/pydantic/pydantic-ai","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:14.413Z","addedAt":"2026-10-08T18:39:31.677Z","updatedAt":"2026-10-08T21:05:51.049Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107290","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107290","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-FPF4-VWCP-V4HP"}]},{"id":"e946f2a2-ea10-4793-b171-446d79612075","slug":"cve-2026-107287","externalId":"CVE-2026-107287","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107287 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.","description":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.7 and 2.52.0, the local web_fetch_tool and the WebFetch local fallback can consume excessive CPU and memory during HTML-to-Markdown conversion of attacker-controlled HTML containing deeply nested block elements. Conversion repeatedly reprocesses accumulated text and can greatly expand intermediate output before the returned-content limit is applied, allowing a model-directed fetch to delay other work in the process. Provider-native web fetching is not affected. This issue is fixed in versions 1.107.7 and 2.52.0.","cveId":"CVE-2026-107287","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":"PyPI","product":"pydantic-ai","affectedVersions":["pkg:pypi/pydantic-ai >= 1.77.0, < 1.107.7","pkg:pypi/pydantic-ai >= 2.0.0b1, < 2.52.0","pkg:pypi/pydantic-ai-slim >= 1.77.0, < 1.107.7","pkg:pypi/pydantic-ai-slim >= 2.0.0b1, < 2.52.0"],"cwes":["CWE-400","CWE-407"],"tags":["nvd","status:received","osv","osv:ghsa-v36g-jcw9-x7cw","ecosystem:pypi","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/2b247add4950bef61d352e7ca8aefbd20539180c","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/commit/2fd38792693da00a3ca5412aeffb436787af3545","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8984","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/pull/8985","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.7","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.52.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-v36g-jcw9-x7cw","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-v36g-jcw9-x7cw","type":"advisory","title":"OSV GHSA-v36g-jcw9-x7cw"},{"url":"https://github.com/pydantic/pydantic-ai","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:17:03.973Z","addedAt":"2026-10-08T16:39:36.009Z","updatedAt":"2026-10-08T23:06:38.388Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107287","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107287","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-V36G-JCW9-X7CW"}]},{"id":"b92dae57-462d-4c1b-9606-202862050871","slug":"cve-2026-107583","externalId":"CVE-2026-107583","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107583 — Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remo…","description":"Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. The route that renders a received message's HTML replaced each reference to an embedded image in place, with work that grew with the square of the number of references, and wrote the image out for every reference while counting it against its size limit only once. A message whose HTML refers to one small embedded image a very large number of times, opened in the webmail by its recipient, therefore keeps one of the listener's four worker threads busy for minutes and makes it build a document of gigabytes, so that a few such messages leave the HTTP listener unable to answer anybody.","cveId":"CVE-2026-107583","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/65","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T12:17:16.633Z","addedAt":"2026-10-08T12:39:41.404Z","updatedAt":"2026-10-08T23:06:37.805Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107583","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107583","note":"authoritative record"}]},{"id":"49c1afaf-9876-49f2-b5de-1be004c63171","slug":"cve-2026-107582","externalId":"CVE-2026-107582","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107582 — Inefficient algorithmic complexity in the REST API (6.3.3 through 6.3.5) and the IMAP PREVIEW response (6.2.22 through 6.3.5) of Progressive Robot …","description":"Inefficient algorithmic complexity in the REST API (6.3.3 through 6.3.5) and the IMAP PREVIEW response (6.2.22 through 6.3.5) of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. To show a snippet of each message in a folder's message list, the server decoded the character entity references of a message that has an HTML part and no text part with a string replacement whose work grew with the square of their number. A received HTML-only message holding a very large number of entity references therefore keeps one of the listener's four worker threads busy for minutes or longer each time the recipient's webmail lists the folder, without the message being opened, so that a few such listings leave the HTTP listener unable to answer anybody. The IMAP PREVIEW response read such text the same way, holding an IMAP thread for each client that asks for the preview of such a message. The flaw is in the server's shared string class, whose replace and remove both ran in quadratic time.","cveId":"CVE-2026-107582","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/67","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T12:17:16.480Z","addedAt":"2026-10-08T12:39:41.396Z","updatedAt":"2026-10-08T23:06:37.785Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107582","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107582","note":"authoritative record"}]},{"id":"a23e7bce-633f-4b8a-9c83-b038e4e15226","slug":"cve-2026-107581","externalId":"CVE-2026-107581","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107581 — Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadratic in the command's lengt…","description":"Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadratic in the command's length or in the number of elements it names, and can be made to hold memory out of proportion to a command. The FETCH data-item parser normalised a BODY[] section with a case-insensitive string replacement that copied the whole item per occurrence and split the item list by repeatedly copying the remainder of the command; the server's case-insensitive search compared a needle afresh at every position, so a long SEARCH TEXT key over a message cost the product of the two lengths; SEARCH message sets and the saved-result marker ($), SORT criteria, HEADER.FIELDS name lists and UID ranges were each read once per message rather than once per command; and a FETCH naming a message's sections very many times read and held every section in memory before sending any. An IMAP command may continue past one line through non-synchronizing literals, so one command can reach about eleven megabytes. The IMAP worker threads are a small pool shared with SMTP and POP3, so a signed-in user sending such commands can make the IMAP, SMTP and POP3 services stop responding (CWE-407) and can consume excessive memory (CWE-400).","cveId":"CVE-2026-107581","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/68","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T12:17:16.320Z","addedAt":"2026-10-08T12:39:41.389Z","updatedAt":"2026-10-08T23:06:37.767Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107581","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107581","note":"authoritative record"}]},{"id":"114fddf2-06b2-4de2-b816-de841141f054","slug":"cve-2026-107580","externalId":"CVE-2026-107580","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107580 — Inefficient algorithmic complexity in the decoding of message header fields in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote un…","description":"Inefficient algorithmic complexity in the decoding of message header fields in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the IMAP, SMTP and POP3 services, or the webmail, unavailable by sending a message. The server unfolded a decoded header value by finding each line break from the end of the value and removing it, moving the rest of the value each time, so its work grew with the square of the number of line breaks, and an RFC 2047 encoded word may decode to any number of them. A received message whose Subject or other header field holds such a value keeps a worker thread busy for minutes or longer each time the value is read: when the recipient's IMAP client searches, sorts or threads the folder by a header, when the webmail lists the folder, and, where configured, when a rule tests a header, a spam tag is added to the Subject or an abuse report is read during delivery. The IMAP worker threads are shared with SMTP and POP3, so a few such messages stop those services responding. The server's reading of a message header from its file also searched everything read so far after each 4,000 bytes, costing seconds for a header of tens of megabytes.","cveId":"CVE-2026-107580","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/69","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T12:17:16.123Z","addedAt":"2026-10-08T12:39:41.380Z","updatedAt":"2026-10-08T23:06:37.751Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107580","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107580","note":"authoritative record"}]},{"id":"b0edaf26-6a8c-4330-9aa0-5b7bbf4e9f84","slug":"cve-2026-107579","externalId":"CVE-2026-107579","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107579 — Inefficient algorithmic complexity in the bounce and complaint processing of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthen…","description":"Inefficient algorithmic complexity in the bounce and complaint processing of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to stop mail delivery by sending messages, when bounce processing or complaint processing is enabled or a mailing list is managed by the server (none is by default). The readers of incoming delivery status notifications (RFC 3464) and abuse feedback reports (RFC 5965) removed the blank lines at the start of the returned headers part two bytes at a time, copying the rest of the part each time, so their work grew with the square of the number of blank lines. A message shaped like such a report, whose headers part begins with a very large number of blank lines within the reader's 2 MB limit, keeps a delivery thread busy for over a minute while it is delivered, and a few such messages a minute keep every delivery thread busy.","cveId":"CVE-2026-107579","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/70","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T12:17:15.940Z","addedAt":"2026-10-08T12:39:41.372Z","updatedAt":"2026-10-08T23:06:37.730Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107579","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107579","note":"authoritative record"}]},{"id":"744f5feb-b451-4329-9639-79f60c7fb17f","slug":"cve-2026-107576","externalId":"CVE-2026-107576","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107576 — Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a…","description":"Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the mail services unavailable by sending a message. Building the canonical header and choosing the header fields named in a signature's h= tag took time growing with the square of the message's header: the 'simple' canonicalisation prepended each continuation line of a folded field to the lines already gathered, and both canonicalisations searched the gathered fields from the bottom for each h= name and erased the match from the middle of the list. A message whose header holds very many fields, or a field folded over very many lines, with a DKIM-Signature the attacker signs for a domain they control, keeps a worker thread busy for tens of seconds per signature; up to ten signatures are evaluated per message by each of the DKIM and DMARC tests, on the threads that serve delivery and SMTP.","cveId":"CVE-2026-107576","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/73","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T12:17:15.487Z","addedAt":"2026-10-08T12:39:41.350Z","updatedAt":"2026-10-08T23:06:37.660Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107576","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107576","note":"authoritative record"}]},{"id":"4fc966dd-b043-4d44-aab0-2ced40a53dfa","slug":"cve-2026-107575","externalId":"CVE-2026-107575","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107575 — Inefficient algorithmic complexity in the SPF macro expansion of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated atta…","description":"Inefficient algorithmic complexity in the SPF macro expansion of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to consume worker-thread time by publishing a crafted SPF record. RFC 7208 section 7.1 requires a name too long to look up to lose whole labels from the left; the server did this by removing one label at a time and copying the rest of the name each time, so the work grew with the square of the expansion. An attacker who publishes an SPF record for a domain they control, with a mechanism whose domain-spec expands through macros to a name far longer than 253 characters, makes the SPF check of a message from that domain take several seconds. The expansion is bounded by SPF's own per-term and per-macro limits, so the loss of availability is partial.","cveId":"CVE-2026-107575","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/74","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T12:17:15.333Z","addedAt":"2026-10-08T12:39:41.343Z","updatedAt":"2026-10-08T23:06:37.636Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107575","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107575","note":"authoritative record"}]},{"id":"a857f962-8e4f-4f9f-b849-fc87a2b5d9ba","slug":"cve-2026-107574","externalId":"CVE-2026-107574","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107574 — Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the mail se…","description":"Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the mail services unavailable. Reading a JSON object kept the first of each duplicated member name by searching the members already read, so an object of N distinct member names cost O(N^2): 1 MB took 8.9 seconds and 4 MB took 300 seconds against the affected code. A remote attacker reaches the reader without an account by mailing a crafted TLS-RPT report (up to 16 MB after decompression) to a hosted domain's published report mailbox, which is read on a delivery thread; a few such reports hold every delivery thread (ten by default), so the server delivers no mail, local or outbound, for over an hour per report. A signed-in account reaches the same 16 MB body through the webmail's own REST routes, holding the REST API's own worker threads. Where no report mailbox is configured, the unauthenticated REST sign-in routes that read a JSON body are capped at 64 KB and are not affected.","cveId":"CVE-2026-107574","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/76","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T12:17:15.177Z","addedAt":"2026-10-08T12:39:41.335Z","updatedAt":"2026-10-08T23:06:37.615Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107574","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107574","note":"authoritative record"}]},{"id":"85f2b1a2-f121-4582-bf2c-e40bdbe0c7b5","slug":"cve-2026-76271","externalId":"CVE-2026-76271","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76271 — In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could…","description":"In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could cause a denial of service against a Representational State Transfer (REST) API endpoint in the Discover Splunk Observability Cloud app. The vulnerability is possible because the app uses an inefficient regular expression to validate input submitted through the endpoint. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access), Splunk Observability Cloud previews (https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.4/observability/splunk-observability-cloud-previews), and restmap.conf (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.0-configuration-file-reference/restmap.conf) in the Splunk documentation.\n\nSplunk Enterprise versions 9.4.x are not affected.","cveId":"CVE-2026-76271","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1001","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00267,"epssPercentile":0.17288,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T21:17:18.050Z","addedAt":"2026-10-07T22:39:36.623Z","updatedAt":"2026-10-08T21:05:44.302Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76271","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76271","note":"authoritative record"}]},{"id":"6d1db9d7-8b8c-4441-b303-3d1d7347d9a6","slug":"cve-2026-95112","externalId":"CVE-2026-95112","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-95112 — When processing issue and comment bodies, Gitea scanned the entire preceding text for action keywords such as \"closes\" or \"fixes\" once per Markdown…","description":"When processing issue and comment bodies, Gitea scanned the entire preceding text for action keywords such as \"closes\" or \"fixes\" once per Markdown link, giving processing time quadratic in the input size. An authenticated user able to submit issue or comment content could send a crafted body of about 1 MB that keeps a CPU core busy for several minutes while holding a database transaction open.","cveId":"CVE-2026-95112","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.gitea.com/release-of-28.0.0/","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39396","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v28.0.0","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-467c-4w7p-8427","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"}],"epssScore":0.00156,"epssPercentile":0.04184,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:34.963Z","addedAt":"2026-10-06T20:39:33.493Z","updatedAt":"2026-10-08T14:40:01.983Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95112","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-95112","note":"authoritative record"}]},{"id":"4180219d-e762-4f62-b383-2e6a93677502","slug":"cve-2026-84429","externalId":"CVE-2026-84429","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84429 — An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.","description":"An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.\n`django.utils.http.parse_header_parameters()` was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request could reach this parsing through headers such as `Accept` or `Content-Type`, for instance via the content negotiation performed by `HttpRequest.accepts()`. The per-call length limit does not bound the combined size of repeated headers.\nEarlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected.\nDjango would like to thank Jisung Chae for reporting this issue.","cveId":"CVE-2026-84429","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://docs.djangoproject.com/en/dev/releases/security/","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://github.com/django/django/commit/3d8f121695c21234aff3071de0d38b6bd38c3f52","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://github.com/django/django/commit/6ecd66e09a383be004a78a3a738ea9727ff07b0e","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://github.com/django/django/commit/7ff7fcc0508864a4bc39693128ace38b1e95a890","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://github.com/django/django/commit/de56deeabd4c48dfb5193f0001469d80102fb367","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://groups.google.com/g/django-announce","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"},{"url":"https://www.djangoproject.com/weblog/2026/oct/06/security-releases/","type":"advisory","title":"6a34fbeb-21d4-45e7-8e0a-62b95bc12c92"}],"epssScore":0.00381,"epssPercentile":0.3001,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T14:17:46.910Z","addedAt":"2026-10-06T15:51:00.357Z","updatedAt":"2026-10-06T15:51:00.357Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84429","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84429","note":"authoritative record"}]},{"id":"807547a5-4851-428c-aa3f-d4df028b255a","slug":"ghsa-r4xh-jqrq-34v2","externalId":"GHSA-r4xh-jqrq-34v2","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line","description":"### Summary\n\n`parse()` has a quadratic-time path in `parseKey`, reachable on default options with ordinary valid input. For every key line and table-header line, `parseKey` (dist/struct.js, lines 58 and 86) finds the dotted-key separator with `ctx.s.indexOf('.', ctx.p)`, where `ctx.s` is the whole document. When a key has no `.` ahead of it, that search runs all the way to the end of the input, and the result is then clamped back to the line terminator `endPtr` - so everything scanned past the current line is wasted. `parseKey` runs once per line, so a document of N dot-free keys costs O(n^2).\n\nThe most ordinary TOML shape triggers it: a flat list of `key = value` lines, or a repeated `[[a]]` table. No dotted keys, no special options, valid input throughout.\n\n### Proof of concept\n\n```js\nimport { parse } from 'smol-toml'\n\nlet doc = ''\nfor (let i = 0; i < 256000; i++) doc += 'k' + i + ' = 1\\n'\n\nconsole.time('parse')\nparse(doc) // ~2.8 MB of valid TOML, default options\nconsole.timeEnd('parse')\n```\n\nDoubling the line count roughly quadruples the time:\n\n| lines | size | parse() |\n|---|---|---|\n| 32k | 0.3 MB | 0.3 s |\n| 64k | 0.7 MB | 1.0 s |\n| 128k | 1.4 MB | 3.5 s |\n| 256k | 2.8 MB | 14 s |\n\n### Impact\nAny service that runs `parse()` on attacker-supplied TOML can be stalled. The work is synchronous, so it blocks the whole event loop, and the quadratic is unbounded: a ~7 MB body pins a core for about a minute, larger bodies for several.\n\n### Patches\nVersion 1.9.0 uses a different implementation for parsing keys which is strictly linear.\n\n### Workarounds\nLimit the maximum document size accepted when parsing arbitrary documents.","cveId":null,"cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":"npm","product":"smol-toml","affectedVersions":["pkg:npm/smol-toml < 1.9.0"],"cwes":["CWE-407"],"tags":["osv","osv:ghsa-r4xh-jqrq-34v2","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-r4xh-jqrq-34v2","type":"advisory","title":"OSV GHSA-r4xh-jqrq-34v2"},{"url":"https://github.com/squirrelchat/smol-toml/security/advisories/GHSA-r4xh-jqrq-34v2","type":"other","title":"OSV web"},{"url":"https://github.com/squirrelchat/smol-toml/commit/99102aa57fc932f760ea9c15b4cf1c181f952d24","type":"other","title":"OSV web"},{"url":"https://github.com/squirrelchat/smol-toml","type":"vendor","title":"OSV package"},{"url":"https://github.com/squirrelchat/smol-toml/releases/tag/v1.9.0","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T23:41:14.000Z","addedAt":"2026-10-06T01:54:26.726Z","updatedAt":"2026-10-06T01:54:26.726Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-r4xh-jqrq-34v2"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-r4xh-jqrq-34v2"}]},{"id":"51e4a4a1-c8f1-4a76-9021-f2382cae6028","slug":"cve-2026-104844","externalId":"CVE-2026-104844","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104844 — PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it.","description":"PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior to 7.1.6, src/parser.js splitWord() can receive a flat selector as one word token carrying many class or ID indexes because period and hash characters are not tokenizer word delimiters. The uniqs() deduplication and per-index class and ID membership checks repeatedly scan the class and ID index arrays, while a separate Sass-interpolation filtering pass also performs repeated linear scanning. Together, these passes make parsing quadratic in the number of indexes and allow a crafted selector to occupy a synchronous parser thread. The maxNestingDepth guard does not mitigate the issue because the hostile selector can have zero nesting depth. Only consumers that synchronously parse untrusted selectors in an exposed request path are affected; ordinary build-time parsing of trusted sources is not affected. This issue is fixed in version 7.1.6.","cveId":"CVE-2026-104844","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"postcss-selector-parser","affectedVersions":["pkg:npm/postcss-selector-parser < 7.1.6"],"cwes":["CWE-400","CWE-407"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-rj75-hqrm-r3gf","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/postcss/postcss-selector-parser/commit/62b191792df0a0bc56062e5a875bc74aae2a51cd","type":"other","title":"OSV web"},{"url":"https://github.com/postcss/postcss-selector-parser/releases/tag/7.1.6","type":"other","title":"OSV web"},{"url":"https://github.com/postcss/postcss-selector-parser/security/advisories/GHSA-rj75-hqrm-r3gf","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-rj75-hqrm-r3gf","type":"advisory","title":"OSV GHSA-rj75-hqrm-r3gf"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104844","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/postcss/postcss-selector-parser","type":"vendor","title":"OSV package"}],"epssScore":0.00394,"epssPercentile":0.31424,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T16:16:46.917Z","addedAt":"2026-10-02T17:50:40.625Z","updatedAt":"2026-10-06T01:54:27.409Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104844","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104844","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-RJ75-HQRM-R3GF"}]},{"id":"32ec800e-321f-4a1d-ac3b-38ac63b94b9f","slug":"cve-2026-96287","externalId":"CVE-2026-96287","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-96287 — Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings.","description":"Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-96287","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/tcg16jr59z5nry066dw7ym60vl25dxt9","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34848,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T13:18:05.627Z","addedAt":"2026-10-02T13:50:41.015Z","updatedAt":"2026-10-02T19:50:41.476Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96287","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-96287","note":"authoritative record"}]},{"id":"3a5d7920-41f9-456a-ac83-b19a8ac3d07f","slug":"cve-2026-94658","externalId":"CVE-2026-94658","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94658 — Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.","description":"Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-94658","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/hv6b1nyk2p15gy5pmtprwo7z9m46mfcx","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34841,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T13:18:03.117Z","addedAt":"2026-10-02T13:50:41.002Z","updatedAt":"2026-10-02T19:50:41.471Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94658","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94658","note":"authoritative record"}]},{"id":"f7e55e7b-fc47-4e1c-985e-3f9707c88d8b","slug":"cve-2026-94655","externalId":"CVE-2026-94655","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94655 — Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.","description":"Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-94655","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-407","CWE-770"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/wdjyf4y115ybgdzz5m3gspo97lcmz1dt","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34842,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T13:18:02.287Z","addedAt":"2026-10-02T13:50:40.987Z","updatedAt":"2026-10-02T19:50:41.454Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94655","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94655","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":143,"totalPages":8,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:57:17.464Z","durationMs":24,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-407"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}