{"success":true,"data":{"threats":[{"id":"f3aa2a85-c55b-4744-995e-c006de139176","slug":"cve-2026-107336","externalId":"CVE-2026-107336","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107336 — Malcolm's front nginx reverse proxy defines a \"Dashboards → Arkime shortcut\" location using a case-insensitive regex matcher but a case-sensitive r…","description":"Malcolm's front nginx reverse proxy defines a \"Dashboards → Arkime shortcut\" location using a case-insensitive regex matcher but a case-sensitive rewrite. A request whose path segment is not exact-lowercase (for example /IDDASH2ARK/...) enters the location (the matcher fires) but evades the rewrite (no redirect is issued), so nginx falls through to the location's proxy_pass to the Arkime backend. That location is the one proxied location in the shipped config that does not include the per-location authentication file, so the request reaches Arkime unauthenticated. The same location also forwards a client-supplied X-Forwarded-User header un-overwritten, and Arkime is configured to trust X-Forwarded-User as the authenticated username — so an unauthenticated network caller can reach the Arkime backend while supplying a forged, auto-provisioned identity.","cveId":"CVE-2026-107336","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290","CWE-441","CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://github.com/cisagov/Malcolm/security/advisories/GHSA-7j32-cf27-cp6h","type":"advisory","title":"ics-cert@hq.dhs.gov"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:20.177Z","addedAt":"2026-10-08T18:39:31.853Z","updatedAt":"2026-10-08T23:06:38.714Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107336","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107336","note":"authoritative record"}]},{"id":"3257cfa9-4647-4984-8c96-0d2af6ddd2cc","slug":"cve-2026-107282","externalId":"CVE-2026-107282","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107282 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13  and 2.16.1, cross-host request replay updates the current request but leaves the target request and related proxy context pointing at the original origin. Connection-pool selection, CONNECT handling, realm selection, and TLS setup can consequently send the original host's path, Host header, Authorization credentials, or plaintext request to the replay destination. Documented ResponseFilter failover and retry paths can trigger the replay. This issue is fixed in versions 3.0.13 and 2.16.1.","cveId":"CVE-2026-107282","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.13","pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1"],"cwes":["CWE-319","CWE-441","CWE-522"],"tags":["nvd","status:received","osv","osv:ghsa-jmqq-x5g9-9p2w","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/15b254514a411623e5f1d8c99ea79c0f82f8a466","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/bbc31aed3b044f9f7a126cf689a8c8d7ad2ae1cb","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-jmqq-x5g9-9p2w","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-jmqq-x5g9-9p2w","type":"advisory","title":"OSV GHSA-jmqq-x5g9-9p2w"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107282","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00189,"epssPercentile":0.07775,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:04.167Z","addedAt":"2026-10-07T22:39:36.815Z","updatedAt":"2026-10-08T21:05:45.138Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107282","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107282","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-JMQQ-X5G9-9P2W"}]},{"id":"544cb365-5679-42a7-9fe3-5882a4d7a3ad","slug":"cve-2026-107232","externalId":"CVE-2026-107232","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107232 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that an HTTP proxy tunnel exists from the last request method rather than the CONNECT result. After a proxy rejects CONNECT, redirect or authentication handlers can write an origin request and its Authorization credentials onto the still-plaintext proxy connection. Basic credentials can be recovered directly, while NTLM responses may be cracked or relayed. This issue is fixed in versions 3.0.12 and 2.16.1.","cveId":"CVE-2026-107232","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-319","CWE-441","CWE-522"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/3a625cb892233c0a6653ac68823a25ffbc80f393","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/a87e7b8c81a6f66a4ce23cd43097fbadd1c788ea","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v9f2-7rw2-gr2x","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00212,"epssPercentile":0.106,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:03.497Z","addedAt":"2026-10-07T22:39:36.784Z","updatedAt":"2026-10-08T21:05:45.028Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107232","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107232","note":"authoritative record"}]},{"id":"f0f0b65b-6d94-42e5-b680-b45a60a7c3e8","slug":"cve-2026-102255","externalId":"CVE-2026-102255","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102255 — A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.","description":"A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.","cveId":"CVE-2026-102255","cvssScore":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-441","CWE-918"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017","type":"advisory","title":"PSIRT@sonicwall.com"}],"epssScore":0.00477,"epssPercentile":0.39223,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T13:17:16.387Z","addedAt":"2026-10-07T14:39:35.059Z","updatedAt":"2026-10-07T16:39:32.100Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102255","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102255","note":"authoritative record"}]},{"id":"3ab65c78-8496-48f9-a10d-b2ff44140b50","slug":"cve-2026-106487","externalId":"CVE-2026-106487","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106487 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 0.21.10, the @backstage/plugin-kubernetes-backend package is affected by unsupported catalog cluster authentication mode in kubernetes backend. Deployments using catalog cluster discovery may be affected when catalog contributors can create or modify kubernetes-cluster Resource entities. With the required endpoint permissions and pod RBAC, the backend can use its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity. The credential is used only with the local in-cluster API endpoint and is not sent to the catalog-supplied endpoint. This issue is fixed in version 0.21.10.","cveId":"CVE-2026-106487","cvssScore":3.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","severity":"low","vendor":"npm","product":"@backstage/plugin-kubernetes-backend","affectedVersions":["pkg:npm/%40backstage/plugin-kubernetes-backend < 0.21.10"],"cwes":["CWE-441"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-h53x-hjx6-25gr","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/c14f8be6908f0f719b16356e5492352311e28946","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-h53x-hjx6-25gr","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-h53x-hjx6-25gr","type":"advisory","title":"OSV GHSA-h53x-hjx6-25gr"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106487","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00221,"epssPercentile":0.11613,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T21:17:17.477Z","addedAt":"2026-10-06T22:39:32.995Z","updatedAt":"2026-10-07T18:42:42.857Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106487","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106487","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-H53X-HJX6-25GR"}]},{"id":"983b80ab-66af-4f5e-90d4-78a073b5ed12","slug":"cve-2026-106462","externalId":"CVE-2026-106462","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106462 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user could cause an affected action to fall back to broader integration credentials and perform operations with more access than intended. This issue is fixed in 1.54.6 when operators also enable scaffolder.requireScmUserCredentials after upgrading.","cveId":"CVE-2026-106462","cvssScore":6.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","severity":"medium","vendor":"npm","product":"@backstage/plugin-scaffolder-backend","affectedVersions":["pkg:npm/%40backstage/plugin-scaffolder-backend < 4.1.0","pkg:npm/%40backstage/plugin-scaffolder-backend-module-github < 0.9.13","pkg:npm/%40backstage/plugin-scaffolder-backend-module-gitlab < 0.11.10","pkg:npm/%40backstage/plugin-scaffolder-backend-module-azure < 0.2.25","pkg:npm/%40backstage/plugin-scaffolder-backend-module-bitbucket-cloud < 0.3.10","pkg:npm/%40backstage/plugin-scaffolder-backend-module-bitbucket-server < 0.2.25"],"cwes":["CWE-441","CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-29gx-h2m3-xw44","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/6fb2a41ea47da37eafe5ea744050ef90be6820c0","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-29gx-h2m3-xw44","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-29gx-h2m3-xw44","type":"advisory","title":"OSV GHSA-29gx-h2m3-xw44"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106462","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage/commit/6fb2a41ea47da37eafe5ea744050","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00171,"epssPercentile":0.05949,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T21:17:17.020Z","addedAt":"2026-10-06T22:39:32.972Z","updatedAt":"2026-10-07T18:42:42.543Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106462","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106462","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-29GX-H2M3-XW44"}]},{"id":"863a3445-ea40-49a1-b4d8-0ab5b5b74425","slug":"cve-2026-94205","externalId":"CVE-2026-94205","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94205 — Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author.","description":"Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. For `pull_request` activity triggered by a maintainer during ordinary triage, such as adding a label, the run was created without requiring approval, while the workflow definition was still taken from the fork head. Where Actions is enabled and a matching runner is registered, fork-controlled workflow code could run on the base repository's runners without an explicit approval.","cveId":"CVE-2026-94205","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-441","CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.gitea.com/release-of-28.0.0/","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/39399","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v28.0.0","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-xh39-mxw9-34pp","type":"advisory","title":"88ee5874-cf24-4952-aea0-31affedb7ff2"}],"epssScore":0.00336,"epssPercentile":0.24961,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:34.733Z","addedAt":"2026-10-06T20:39:33.477Z","updatedAt":"2026-10-07T22:39:36.252Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94205","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94205","note":"authoritative record"}]},{"id":"c3fffd78-ea3e-4d2c-b0ca-4a22a84d78dd","slug":"cve-2026-106427","externalId":"CVE-2026-106427","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106427 — Confused deputy in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a p…","description":"Confused deputy in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)","cveId":"CVE-2026-106427","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-441"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/513423334","type":"advisory","title":"Permissions Required"}],"epssScore":0.00159,"epssPercentile":0.04419,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:12.600Z","addedAt":"2026-10-06T20:39:32.409Z","updatedAt":"2026-10-08T18:39:30.377Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106427","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106427","note":"authoritative record"}]},{"id":"f0b7030d-304d-4793-966d-6dfca4012d01","slug":"cve-2026-106359","externalId":"CVE-2026-106359","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106359 — Confused deputy in DeviceBoundSessionCredentials in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via …","description":"Confused deputy in DeviceBoundSessionCredentials in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","cveId":"CVE-2026-106359","cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-441"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"advisory","title":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/500532594","type":"advisory","title":"chrome-cve-admin@google.com"}],"epssScore":0.00235,"epssPercentile":0.13188,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:04.853Z","addedAt":"2026-10-06T20:39:31.887Z","updatedAt":"2026-10-06T20:39:31.887Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106359","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106359","note":"authoritative record"}]},{"id":"8c5bd16c-33d4-4039-a4b3-9523bc309a80","slug":"cve-2026-106326","externalId":"CVE-2026-106326","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106326 — Confused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions into a pr…","description":"Confused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium)","cveId":"CVE-2026-106326","cvssScore":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-441"],"tags":["nvd","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/511745101","type":"advisory","title":"Permissions Required"}],"epssScore":0.00082,"epssPercentile":0.00191,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:00.900Z","addedAt":"2026-10-06T20:39:31.631Z","updatedAt":"2026-10-08T16:39:34.796Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106326","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106326","note":"authoritative record"}]},{"id":"0c08b2d1-9052-4e1a-b859-b930a5059752","slug":"cve-2026-106301","externalId":"CVE-2026-106301","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106301 — Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to b…","description":"Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106301","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-441"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/523750306","type":"advisory","title":"Permissions Required"}],"epssScore":0.00224,"epssPercentile":0.11934,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:58.153Z","addedAt":"2026-10-06T20:39:31.439Z","updatedAt":"2026-10-08T14:40:01.931Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106301","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106301","note":"authoritative record"}]},{"id":"1e11239d-badd-40bf-8c19-aa7fe04b5045","slug":"cve-2026-106286","externalId":"CVE-2026-106286","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106286 — Confused deputy in Omnibox in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via crafted network traffic.","description":"Confused deputy in Omnibox in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)","cveId":"CVE-2026-106286","cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-441"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"advisory","title":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/497148613","type":"advisory","title":"chrome-cve-admin@google.com"}],"epssScore":0.00174,"epssPercentile":0.06274,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:56.387Z","addedAt":"2026-10-06T20:39:31.317Z","updatedAt":"2026-10-06T20:39:31.317Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106286","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106286","note":"authoritative record"}]},{"id":"f340b73e-3b8f-41b3-82b9-9c309809c681","slug":"cve-2026-106266","externalId":"CVE-2026-106266","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106266 — Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to b…","description":"Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106266","cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-441"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"advisory","title":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/501914204","type":"advisory","title":"chrome-cve-admin@google.com"}],"epssScore":0.00189,"epssPercentile":0.07765,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:54.110Z","addedAt":"2026-10-06T20:39:31.160Z","updatedAt":"2026-10-06T20:39:31.160Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106266","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106266","note":"authoritative record"}]},{"id":"8f944818-62ac-4dd5-8b4a-72658b29f341","slug":"cve-2026-106228","externalId":"CVE-2026-106228","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106228 — Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potent…","description":"Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106228","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-441"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/517689673","type":"advisory","title":"Permissions Required"}],"epssScore":0.00357,"epssPercentile":0.27398,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:49.563Z","addedAt":"2026-10-06T20:39:30.845Z","updatedAt":"2026-10-07T18:39:30.357Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106228","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106228","note":"authoritative record"}]},{"id":"7e7c0827-06db-40e9-97f6-fc55c19bdf23","slug":"cve-2026-106221","externalId":"CVE-2026-106221","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106221 — Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass …","description":"Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","cveId":"CVE-2026-106221","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-441"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/540049672","type":"advisory","title":"Permissions Required"}],"epssScore":0.00303,"epssPercentile":0.21175,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:48.783Z","addedAt":"2026-10-06T20:39:30.789Z","updatedAt":"2026-10-08T02:39:29.737Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106221","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106221","note":"authoritative record"}]},{"id":"c8809af4-517a-4399-80fb-0f8ba874268b","slug":"cve-2026-106188","externalId":"CVE-2026-106188","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106188 — Confused deputy in SignIn in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into…","description":"Confused deputy in SignIn in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106188","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-441"],"tags":["nvd","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/515477538","type":"advisory","title":"Permissions Required"}],"epssScore":0.00222,"epssPercentile":0.11685,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:44.860Z","addedAt":"2026-10-06T20:39:30.526Z","updatedAt":"2026-10-08T16:39:34.740Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106188","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106188","note":"authoritative record"}]},{"id":"bf8bb3fe-90cf-4785-903e-81cc94f188c2","slug":"cve-2026-55270","externalId":"CVE-2026-55270","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-55270 — In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy.","description":"In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-55270","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"android","affectedVersions":["14.0","15.0","16.0","17.0"],"cwes":["CWE-441"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://source.android.com/docs/security/bulletin/2026/2026-10-01"],"references":[{"url":"https://source.android.com/docs/security/bulletin/2026/2026-10-01","type":"patch","title":"Patch"}],"epssScore":0.00068,"epssPercentile":0.00023,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:24.097Z","addedAt":"2026-10-05T19:50:42.926Z","updatedAt":"2026-10-07T16:39:30.368Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55270","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-55270","note":"authoritative record"}]},{"id":"3dcbe2e5-b7b3-4ebc-bcea-6d11d04d5c36","slug":"cve-2026-28648","externalId":"CVE-2026-28648","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-28648 — In Settings, there is a possible permission bypass due to a confused deputy.","description":"In Settings, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-28648","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"android","affectedVersions":["14.0","15.0","16.0"],"cwes":["CWE-441"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://source.android.com/docs/security/bulletin/aaos/2026/2026-10-01","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00068,"epssPercentile":0.00024,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:20.300Z","addedAt":"2026-10-05T19:50:42.865Z","updatedAt":"2026-10-07T14:39:32.536Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28648","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-28648","note":"authoritative record"}]},{"id":"d0f5e16b-1b29-4896-acab-bf98ab64244b","slug":"cve-2026-93320","externalId":"CVE-2026-93320","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93320 — BuildKit may be tricked into performing file actions with special file inodes where regular files are expected.","description":"BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.","cveId":"CVE-2026-93320","cvssScore":6,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-441"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/moby/buildkit/releases/tag/v0.33.1","type":"advisory","title":"security@docker.com"},{"url":"https://github.com/moby/buildkit/security/advisories/GHSA-9728-qjrv-2xh2","type":"advisory","title":"security@docker.com"}],"epssScore":0.00114,"epssPercentile":0.01356,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T18:17:38.353Z","addedAt":"2026-10-05T19:50:42.673Z","updatedAt":"2026-10-06T15:50:57.953Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93320","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93320","note":"authoritative record"}]},{"id":"92895c26-c082-4cc6-bb78-7586c3635f00","slug":"cve-2026-103922","externalId":"CVE-2026-103922","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103922 — Capacitor is a cross-platform native runtime for web applications.","description":"Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to /_capacitor_http_interceptor_. The native proxy can fetch an attacker-selected URL and return the response as a document at the application's own origin, allowing script in that response to access same-origin storage, cookies, and registered Capacitor plugin capabilities. Applications remain affected when CapacitorHttp is disabled because affected releases serve the proxy path regardless of that setting. This issue is fixed in versions 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1.","cveId":"CVE-2026-103922","cvssScore":9.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","severity":"critical","vendor":"npm","product":"@capacitor/android","affectedVersions":["pkg:npm/%40capacitor/android >= 6.0.0, < 6.2.2","pkg:npm/%40capacitor/android >= 7.0.0, < 7.6.9","pkg:npm/%40capacitor/ios >= 6.0.0, < 6.2.2","pkg:npm/%40capacitor/ios >= 7.0.0, < 7.6.9","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 6.0.0, < 6.2.2","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 7.0.0, < 7.6.9","pkg:maven/com.capacitorjs/core >= 6.0.0, < 6.2.2","pkg:maven/com.capacitorjs/core >= 7.0.0, < 7.6.9","pkg:npm/%40capacitor/android >= 8.5.0, < 8.5.1","pkg:npm/%40capacitor/ios >= 8.5.0, < 8.5.1","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 8.5.0, < 8.5.1","pkg:maven/com.capacitorjs/core >= 8.5.0, < 8.5.1","pkg:maven/com.capacitorjs/core >= 8.3.5, < 8.4.3","pkg:npm/%40capacitor/android >= 8.3.5, < 8.4.3","pkg:npm/%40capacitor/ios >= 8.3.5, < 8.4.3","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 8.3.5, < 8.4.3","pkg:swift/github.com/ionic-team/capacitor-swift-pm >= 8.0.0, <= 8.3.4","pkg:maven/com.capacitorjs/core >= 8.0.0, <= 8.3.4","pkg:npm/%40capacitor/android >= 8.0.0, <= 8.3.4","pkg:npm/%40capacitor/ios >= 8.0.0, <= 8.3.4"],"cwes":["CWE-346","CWE-441"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-rvm3-566m-v7fv","ecosystem:npm","ecosystem:swifturl","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ionic-team/capacitor/commit/430356a91e1419fc66862dc09835081aa501677e","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/80b6c5e81d062e1e158914040f49e044d95b7ccb","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/85ccc44151fdd5ae5e0d806d875766ef4b84ad5d","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/af9a287fef45f0ac68ce640cb42fed2d06b0f1b4","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/d5e3170ba0ff155fc542b7e6d16cff5201406540","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/commit/ee586ae680887ba99d066616f976db149542d922","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/releases/tag/8.5.1","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor/security/advisories/GHSA-rvm3-566m-v7fv","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-rvm3-566m-v7fv","type":"advisory","title":"OSV GHSA-rvm3-566m-v7fv"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103922","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/ionic-team/capacitor/commit/745b5f805bf77bc6463977cc7d718cd9de44ccbc","type":"other","title":"OSV web"},{"url":"https://github.com/ionic-team/capacitor","type":"vendor","title":"OSV package"}],"epssScore":0.00213,"epssPercentile":0.10633,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T18:17:12.840Z","addedAt":"2026-10-01T19:50:41.041Z","updatedAt":"2026-10-06T01:54:27.398Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103922","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103922","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-RVM3-566M-V7FV"}]}],"pagination":{"page":1,"limit":20,"total":121,"totalPages":7,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:55:25.168Z","durationMs":22,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-441"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}