{"success":true,"data":{"threats":[{"id":"ff218a47-3d55-412d-8210-b92f6184f3cb","slug":"cve-2026-107715","externalId":"CVE-2026-107715","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107715 — The Mechanize library is used for automating interaction with websites.","description":"The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize::HTTP::Agent#request_add_headers even after Mechanize::HTTP::Agent#response_redirect strips per-request headers, and the protected header lists omit Proxy-Authorization and Cookie2. An attacker who controls a redirect target can capture bearer tokens or session cookies supplied through request_headers= or the per-request headers argument, while Mechanize#cookie_jar and Mechanize::HTTP::AuthStore are not affected. This issue is fixed in version 2.14.1.","cveId":"CVE-2026-107715","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-200","CWE-522"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/sparklemotion/mechanize/commit/02a1235842d6eda8d4a5a3d8f13aba2cecf52e4f","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/commit/94e0902867296be804f36eccbb47acf7d5018745","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/commit/ac49abf2869297d83c3b11bbfb8b18e63b588c95","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/pull/676","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/releases/tag/v2.14.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/security/advisories/GHSA-2mwr-xjcg-37j7","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:27.163Z","addedAt":"2026-10-08T23:06:40.059Z","updatedAt":"2026-10-08T23:06:40.059Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107715","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107715","note":"authoritative record"}]},{"id":"67ef5980-c1a7-471e-9656-9514382731c7","slug":"cve-2026-107714","externalId":"CVE-2026-107714","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107714 — The Mechanize library is used for automating interaction with websites.","description":"The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize::HTTP::Agent#response_redirect treats redirects as same-origin when the host matches without consistently comparing scheme and port. A same-host HTTPS-to-HTTP redirect can send Authorization and Cookie headers over cleartext, while a same-host redirect to another port can send a caller-supplied Cookie header to a different service. Cookies in Mechanize#cookie_jar remain scoped separately; the issue affects caller-supplied headers and can disclose credentials without affecting integrity or availability. This issue is fixed in version 2.14.1.","cveId":"CVE-2026-107714","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-200","CWE-319","CWE-522"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/sparklemotion/mechanize/commit/02a1235842d6eda8d4a5a3d8f13aba2cecf52e4f","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/commit/2f97fe358a91928e5e48221f2ec5cb50fa1a43ba","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/pull/676","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/releases/tag/v2.14.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/security/advisories/GHSA-5jgv-wc2m-xv99","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:27.003Z","addedAt":"2026-10-08T23:06:40.044Z","updatedAt":"2026-10-08T23:06:40.044Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107714","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107714","note":"authoritative record"}]},{"id":"45fd8b4a-2495-4fee-b880-bb87977b62ef","slug":"cve-2026-107399","externalId":"CVE-2026-107399","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107399 — The Mechanize library is used for automating interaction with websites.","description":"The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A page containing a meta refresh to another origin causes headers configured through Mechanize#request_headers= to be reapplied to the refresh request, allowing an attacker who controls content in the crawl to capture bearer tokens or session cookies. The default configuration is not affected because follow_meta_refresh is false, and the exposure is limited to caller-supplied default headers. This issue is fixed in version 2.14.1.","cveId":"CVE-2026-107399","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-200","CWE-522"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/sparklemotion/mechanize/commit/02a1235842d6eda8d4a5a3d8f13aba2cecf52e4f","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/commit/84c74df87d15f5d119df268ba6aa79bc1e16a2c3","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/pull/676","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/releases/tag/v2.14.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/security/advisories/GHSA-c6rp-p8xm-4q9f","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:26.683Z","addedAt":"2026-10-08T23:06:40.020Z","updatedAt":"2026-10-08T23:06:40.020Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107399","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107399","note":"authoritative record"}]},{"id":"e99e3976-1e8b-4a63-a0c8-66f46f3395a9","slug":"cve-2026-105833","externalId":"CVE-2026-105833","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105833 — EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\\Service that allows users with Email Account sc…","description":"EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\\Service that allows users with Email Account scope access to retrieve other users' IMAP passwords. Attackers who know a victim's Email Account record ID can request that record to steal stored IMAP credentials and access the victim's mailbox.","cveId":"CVE-2026-105833","cvssScore":8.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-522"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/espocrm/espocrm/security/advisories/GHSA-pj52-qx2q-4qfp","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/espocrm-before-10.0.5-idor-via-personalaccount-service-exposes-imap-passwords","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:35.913Z","addedAt":"2026-10-08T16:39:35.726Z","updatedAt":"2026-10-08T18:39:31.507Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105833","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105833","note":"authoritative record"}]},{"id":"c5b3f807-3bcf-497d-afe2-f0f0027a018e","slug":"cve-2026-107503","externalId":"CVE-2026-107503","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107503 — Unvalidated environments URL allows OAuth authorization code + PKCE verifier theft and account takeover via injected OIDC authority in Ditto Explor…","description":"Unvalidated environments URL allows OAuth authorization code + PKCE verifier theft and account takeover via injected OIDC authority in Ditto Explorer in Eclipse Ditto Ditto Explorer [3.6.0,3.9.7] allows a craft link set an attacker-controlled OIDC authority with autoSso enabled. The UI then automatically starts a login at the genuine identity provider but exchanges the returned authorization code together with its PKCE code_verifier at an attacker-controlled token endpoint. This lets the attacker redeem the code for the victim's access and refresh tokens. Alternatively, an attacker-controlled api_uri causes the UI to send the victim's bearer token or Basic credentials to the attacker. Because the configuration is persisted, later visits to the UI without the crafted link repeat the token theft.","cveId":"CVE-2026-107503","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-15","CWE-346","CWE-522"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/eclipse-ditto/ditto/security/advisories/GHSA-8767-g5qv-9jcf","type":"advisory","title":"emo@eclipse.org"},{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/380","type":"advisory","title":"emo@eclipse.org"},{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/1207","type":"advisory","title":"emo@eclipse.org"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T10:17:08.457Z","addedAt":"2026-10-08T10:39:34.980Z","updatedAt":"2026-10-08T21:05:47.863Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107503","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107503","note":"authoritative record"}]},{"id":"401e92cd-a55f-43b9-aee6-2ad0badc53e8","slug":"cve-2026-87428","externalId":"CVE-2026-87428","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87428 — In Brocade ASCG before 3.5.0, a  local unauthorized user on the ASCG VM who can issue a request to the SANnav host network namespace can extract st…","description":"In Brocade ASCG before 3.5.0, a  local unauthorized user on the ASCG VM who can issue a request to the SANnav host network namespace can extract stored management credentials for onboarded SANnav instances and compromise connected Brocade SANnav servers or managed Brocade Fibre Channel switches.","cveId":"CVE-2026-87428","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-522"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/38390","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00096,"epssPercentile":0.00642,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T07:16:33.400Z","addedAt":"2026-10-08T08:39:29.365Z","updatedAt":"2026-10-08T21:05:47.736Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87428","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87428","note":"authoritative record"}]},{"id":"28a7d82c-d466-46eb-880d-348bcd39b05c","slug":"cve-2026-107285","externalId":"CVE-2026-107285","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107285 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT, but NettyRequestFactory.newNettyRequest and requestUri decide whether to attach proxy authentication and an absolute-form target only from whether the URI is secure. Because ws is not marked secure, the tunneled WebSocket upgrade sent to the origin includes the proxy's Proxy-Authorization value. Basic credentials are directly recoverable and Digest responses can be replayed or cracked offline. This issue is fixed in versions 3.0.12 and 2.16.1.","cveId":"CVE-2026-107285","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.12","pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1"],"cwes":["CWE-319","CWE-522"],"tags":["nvd","status:received","osv","osv:ghsa-3wp9-xfwm-rjjf","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/6e9cb75a9b7259353f983fc90ca28b1da3742e18","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/c4feab0f7f86d61505a48e40d383c8a375a22e18","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-3wp9-xfwm-rjjf","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-3wp9-xfwm-rjjf","type":"advisory","title":"OSV GHSA-3wp9-xfwm-rjjf"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107285","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00206,"epssPercentile":0.09691,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:04.637Z","addedAt":"2026-10-07T22:39:36.836Z","updatedAt":"2026-10-08T21:05:45.227Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107285","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107285","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-3WP9-XFWM-RJJF"}]},{"id":"3257cfa9-4647-4984-8c96-0d2af6ddd2cc","slug":"cve-2026-107282","externalId":"CVE-2026-107282","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107282 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13  and 2.16.1, cross-host request replay updates the current request but leaves the target request and related proxy context pointing at the original origin. Connection-pool selection, CONNECT handling, realm selection, and TLS setup can consequently send the original host's path, Host header, Authorization credentials, or plaintext request to the replay destination. Documented ResponseFilter failover and retry paths can trigger the replay. This issue is fixed in versions 3.0.13 and 2.16.1.","cveId":"CVE-2026-107282","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.13","pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1"],"cwes":["CWE-319","CWE-441","CWE-522"],"tags":["nvd","status:received","osv","osv:ghsa-jmqq-x5g9-9p2w","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/15b254514a411623e5f1d8c99ea79c0f82f8a466","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/bbc31aed3b044f9f7a126cf689a8c8d7ad2ae1cb","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-jmqq-x5g9-9p2w","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-jmqq-x5g9-9p2w","type":"advisory","title":"OSV GHSA-jmqq-x5g9-9p2w"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107282","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00189,"epssPercentile":0.07775,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:04.167Z","addedAt":"2026-10-07T22:39:36.815Z","updatedAt":"2026-10-08T21:05:45.138Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107282","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107282","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-JMQQ-X5G9-9P2W"}]},{"id":"544cb365-5679-42a7-9fe3-5882a4d7a3ad","slug":"cve-2026-107232","externalId":"CVE-2026-107232","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107232 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that an HTTP proxy tunnel exists from the last request method rather than the CONNECT result. After a proxy rejects CONNECT, redirect or authentication handlers can write an origin request and its Authorization credentials onto the still-plaintext proxy connection. Basic credentials can be recovered directly, while NTLM responses may be cracked or relayed. This issue is fixed in versions 3.0.12 and 2.16.1.","cveId":"CVE-2026-107232","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-319","CWE-441","CWE-522"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/3a625cb892233c0a6653ac68823a25ffbc80f393","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/a87e7b8c81a6f66a4ce23cd43097fbadd1c788ea","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.12","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v9f2-7rw2-gr2x","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00212,"epssPercentile":0.106,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:03.497Z","addedAt":"2026-10-07T22:39:36.784Z","updatedAt":"2026-10-08T21:05:45.028Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107232","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107232","note":"authoritative record"}]},{"id":"fb027b1d-b52d-48a8-b768-368532a235a4","slug":"cve-2026-107231","externalId":"CVE-2026-107231","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107231 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challenge that yields no usable nonce as a Basic challenge. A malicious origin or proxy can label a challenge Digest while omitting or emptying the nonce, causing the client to resend the username and password using reversible Basic authentication. Both origin and proxy challenge parsers are affected. This issue is fixed in versions 3.0.13 and 2.16.1.","cveId":"CVE-2026-107231","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0.Beta1, < 3.0.13","pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1"],"cwes":["CWE-319","CWE-522","CWE-757"],"tags":["nvd","status:received","osv","osv:ghsa-rqf5-2wxv-rjf4","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/8376866aa9b5a7653ad19db9d472692f875caa83","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/c8d639bf6ac341d377d610a93570bcd15565f1a6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rqf5-2wxv-rjf4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-rqf5-2wxv-rjf4","type":"advisory","title":"OSV GHSA-rqf5-2wxv-rjf4"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107231","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00237,"epssPercentile":0.13486,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:03.320Z","addedAt":"2026-10-07T22:39:36.777Z","updatedAt":"2026-10-08T21:05:45.000Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107231","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107231","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-RQF5-2WXV-RJF4"}]},{"id":"565273f4-964a-4c15-9958-f81da539911e","slug":"cve-2026-76483","externalId":"CVE-2026-76483","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76483 — As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Sma…","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. &nbsp;\r\n\r\nThe vulnerabilities tracked by CVE-2026-76483 are related to issues with insufficiently protected credentials that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-522.","cveId":"CVE-2026-76483","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-522"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ssm-Ph77wdhf","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00222,"epssPercentile":0.11783,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:17:00.910Z","addedAt":"2026-10-07T18:39:31.520Z","updatedAt":"2026-10-08T21:05:43.006Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76483","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76483","note":"authoritative record"}]},{"id":"88ac6a83-2709-45e4-ab20-2c5c3d2bd557","slug":"cve-2026-105138","externalId":"CVE-2026-105138","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105138 — Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set…","description":"Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set on MCP catalog entries by admins or power users. Basic users granted an entry by access control rules can request GET /api/all-mcps/entries/{entry_id} to obtain plaintext API keys or tokens and abuse them against backend services.","cveId":"CVE-2026-105138","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-522"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/obot-platform/obot","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/blob/774972b92d86e0fbc7e0e9b36fdd06612859df9c/pkg/api/authz/resources.go#L27","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/blob/774972b92d86e0fbc7e0e9b36fdd06612859df9c/pkg/api/handlers/mcp.go#L206-L212","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/commit/644a1fd60a66125ced3de10b350a983e933def7a","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/releases/tag/v0.26.2","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/security/advisories/GHSA-q5wf-87f5-cxgq","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/obot-0.12.0-before-0.26.2-credential-exposure-via-mcp-catalog-entry-api","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00263,"epssPercentile":0.16695,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T13:17:16.977Z","addedAt":"2026-10-07T14:39:35.079Z","updatedAt":"2026-10-07T18:39:30.939Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105138","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105138","note":"authoritative record"}]},{"id":"2a483093-7ad7-4cd4-873c-05d1abf0c155","slug":"cve-2026-101331","externalId":"CVE-2026-101331","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-101331 — IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to insufficiently protected c…","description":"IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to insufficiently protected credentials.","cveId":"CVE-2026-101331","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":"langflow","product":"langflow","affectedVersions":[">= 1.0.0, < 1.12.3"],"cwes":["CWE-522"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7290694","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.0026,"epssPercentile":0.16223,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T01:16:33.957Z","addedAt":"2026-10-07T02:39:28.991Z","updatedAt":"2026-10-08T18:39:30.405Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101331","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-101331","note":"authoritative record"}]},{"id":"987229d0-4a5d-4268-8d7b-06518a3176ac","slug":"cve-2026-104850","externalId":"CVE-2026-104850","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104850 — MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients.","description":"MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP server a client connected to decide which authorization server received the client's OAuth credentials. Stored and pre-provisioned credentials were not bound to the authorization server they belong to. A malicious or compromised MCP server could name its own authorization server in its protected resource metadata. Without any user interaction, the client would send that server the `refresh_token` and `client_secret` stored from an earlier sign-in (1.x), or the configured `client_secret` or signed assertion of a bundled non-interactive provider (1.x and 2.x). Only those applications that use the SDK as an MCP client over HTTP with an `authProvider`: your own `OAuthClientProvider`, or the bundled `ClientCredentialsProvider`, `PrivateKeyJwtProvider`, `StaticPrivateKeyJwtProvider` or (2.x) `CrossAppAccessProvider` and that may connect to an MCP server the owners does not fully trust while holding credentials for a legitimate authorization server are affected. `@modelcontextprotocol/sdk` 1.31.0 (1.x) and `@modelcontextprotocol/client` 2.2.0 (2.x) patch the issue. A workaround for those who cannot upgrade is available. 2.0.0 and 2.1.0 already accept `expectedIssuer`. On 1.x, the only workaround is to connect OAuth-enabled clients only to MCP servers you trust.","cveId":"CVE-2026-104850","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":"npm","product":"@modelcontextprotocol/sdk","affectedVersions":["pkg:npm/%40modelcontextprotocol/sdk >= 1.12.0, < 1.31.0","pkg:npm/%40modelcontextprotocol/client >= 2.0.0, < 2.2.0"],"cwes":["CWE-345","CWE-522"],"tags":["nvd","status:received","osv","osv:ghsa-6qxp-vccf-f47h","ecosystem:npm","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/modelcontextprotocol/typescript-sdk/commit/edd12e282620ebf770d67316f19cf91d4112a1bd","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/modelcontextprotocol/typescript-sdk/pull/2887","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/modelcontextprotocol/typescript-sdk/releases/tag/v2.2.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/modelcontextprotocol/typescript-sdk/security/advisories/GHSA-6qxp-vccf-f47h","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-6qxp-vccf-f47h","type":"advisory","title":"OSV GHSA-6qxp-vccf-f47h"},{"url":"https://github.com/modelcontextprotocol/typescript-sdk","type":"vendor","title":"OSV package"}],"epssScore":0.00176,"epssPercentile":0.06479,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T17:17:15.827Z","addedAt":"2026-10-06T17:50:42.536Z","updatedAt":"2026-10-06T20:39:29.874Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104850","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104850","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-6QXP-VCCF-F47H"}]},{"id":"4cc6f56e-7151-4e0f-ac8e-4101484aab16","slug":"cve-2026-105763","externalId":"CVE-2026-105763","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105763 — Twenty is an open-source CRM (customer relationship management) platform.","description":"Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL connectedAccounts query returned connectionParameters from ConnectedAccountDTO for every connected account in a workspace, including plaintext IMAP, SMTP, and CalDAV passwords, because the field was not hidden and the lookup did not enforce the calling user's identity or account visibility. A normal workspace member could obtain other members' external-service credentials and use them to access mail or calendars and potentially reset third-party accounts. Google and Microsoft OAuth-only workspaces were not affected. This issue is fixed in version 2.7.0.","cveId":"CVE-2026-105763","cvssScore":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-522"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/twentyhq/twenty/commit/57f13c9b9230f3c4c293ea6f3d8901990e6902c4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/twentyhq/twenty/pull/20673","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/twentyhq/twenty/security/advisories/GHSA-mq5c-qp77-2cv3","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00277,"epssPercentile":0.18501,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T00:16:33.247Z","addedAt":"2026-10-06T01:50:41.207Z","updatedAt":"2026-10-08T04:39:32.247Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105763","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105763","note":"authoritative record"}]},{"id":"6555bfed-a3fa-4a54-b45c-4defe45aaac2","slug":"cve-2026-105742","externalId":"CVE-2026-105742","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105742 — Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem.","description":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.95.0 until 2.132.0, the HTML image resource loader in docling/backend/utils/image_resource_loader.py forwards headers configured through the HTMLBackendOptions.headers setting to every remote image URL named by an untrusted document when enable_remote_fetch=True and fetch_images=True. The loader does not restrict those credentials to the source document's origin, allowing requests that carry custom headers such as API keys and cookies to follow cross-origin redirects and expose the caller's configured credentials to a document author. The default configuration is not affected because remote fetching and configured headers are required. This issue is fixed in 2.132.0.","cveId":"CVE-2026-105742","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","severity":"medium","vendor":"docling","product":"docling","affectedVersions":[">= 2.95.0, < 2.132.0","pkg:pypi/docling >= 2.95.0, < 2.132.0","pkg:pypi/docling-slim >= 2.95.0, < 2.132.0"],"cwes":["CWE-201","CWE-522"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed","osv","osv:ghsa-p3fw-7699-7926","ecosystem:pypi","osv:pysec-2026-4189"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/docling-project/docling/commit/5e469137f275ffc443306a30d12a3a45bceb80fb","https://github.com/docling-project/docling/pull/4420","https://github.com/docling-project/docling/security/advisories/GHSA-p3fw-7699-7926"],"references":[{"url":"https://github.com/docling-project/docling/commit/5e469137f275ffc443306a30d12a3a45bceb80fb","type":"patch","title":"OSV fix"},{"url":"https://github.com/docling-project/docling/pull/4420","type":"patch","title":"OSV fix"},{"url":"https://github.com/docling-project/docling/releases/tag/v2.132.0","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/docling-project/docling/security/advisories/GHSA-p3fw-7699-7926","type":"patch","title":"OSV fix"},{"url":"https://osv.dev/vulnerability/GHSA-p3fw-7699-7926","type":"advisory","title":"OSV GHSA-p3fw-7699-7926"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105742","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/docling-project/docling","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4189","type":"advisory","title":"OSV PYSEC-2026-4189"}],"epssScore":0.00226,"epssPercentile":0.1228,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T22:16:56.867Z","addedAt":"2026-10-05T23:50:40.359Z","updatedAt":"2026-10-08T12:42:40.325Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105742","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105742","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-P3FW-7699-7926"}]},{"id":"272d22e9-6e9a-4d38-afc6-d6f99ee5b1af","slug":"cve-2026-86671","externalId":"CVE-2026-86671","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86671 — In Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POST /api/factory/resolver` endpoints pass an attacker-controlled URL to …","description":"In Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POST /api/factory/resolver` endpoints pass an attacker-controlled URL to `URLFetcher.fetch()`, which calls `new URL(url).openConnection()` with no scheme or host allow-list and returns the response body to the caller. Any authenticated Che user can read arbitrary local files via the file:// scheme (including the pod's Kubernetes service-account token at `file:///var/run/secrets/kubernetes.io/serviceaccount/token`), reach internal HTTP services and cloud instance metadata endpoints (169.254.169.254), and have their stored SCM personal access token attached as an `Authorization` header to a host of their choosing. The same credential-forwarding behavior also fires when a victim opens a workspace from a malicious devfile whose `parent.uri` points to an attacker-controlled server, enabling exfiltration of the victim's SCM PAT without direct API access. No fix is available.","cveId":"CVE-2026-86671","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-73","CWE-522","CWE-918"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/278","type":"advisory","title":"emo@eclipse.org"},{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/620","type":"advisory","title":"emo@eclipse.org"},{"url":"https://redhat.atlassian.net/browse/CRW-11956","type":"advisory","title":"emo@eclipse.org"}],"epssScore":0.00252,"epssPercentile":0.15252,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T17:17:16.910Z","addedAt":"2026-10-05T17:50:43.082Z","updatedAt":"2026-10-06T15:50:57.853Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86671","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86671","note":"authoritative record"}]},{"id":"8cdaeb5f-03ad-4b13-a3b9-85417e6fa8e9","slug":"cve-2026-93474","externalId":"CVE-2026-93474","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93474 — Charging station authentication identifiers are publicly accessible via web-based mapping platforms.","description":"Charging station authentication identifiers are publicly accessible via web-based mapping platforms.","cveId":"CVE-2026-93474","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-522"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-02.json","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-02","type":"advisory","title":"ics-cert@hq.dhs.gov"}],"epssScore":0.00202,"epssPercentile":0.09267,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T22:16:55.873Z","addedAt":"2026-10-02T23:50:39.678Z","updatedAt":"2026-10-06T15:50:55.803Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93474","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93474","note":"authoritative record"}]},{"id":"b9e91565-44e6-4030-83f0-9a316ea5cb89","slug":"cve-2026-104051","externalId":"CVE-2026-104051","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104051 — PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and …","description":"PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.","cveId":"CVE-2026-104051","cvssScore":8.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-522"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/HaschekSolutions/pictshare/commit/ce5fc474e89769efeae25fee763894bcce3412e3","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/HaschekSolutions/pictshare/releases/tag/v3.7.1","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/pictshare-sensitive-information-disclosure-via-info-api","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00373,"epssPercentile":0.29126,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T22:17:00.833Z","addedAt":"2026-10-01T23:50:39.504Z","updatedAt":"2026-10-06T03:50:41.596Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104051","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104051","note":"authoritative record"}]},{"id":"1a634012-7f7c-4dcf-ab8a-3e58384a232c","slug":"cve-2026-103256","externalId":"CVE-2026-103256","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103256 — n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credent…","description":"n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.","cveId":"CVE-2026-103256","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-522"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-gx6g-2hm7-c4xf","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-2.39.6-and-2.40-x-before-2.40.1-credentials-leak-via-preauthentication-hook","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00211,"epssPercentile":0.10437,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T11:17:19.913Z","addedAt":"2026-10-01T11:50:39.856Z","updatedAt":"2026-10-01T15:50:41.277Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103256","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103256","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":257,"totalPages":13,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:10:58.980Z","durationMs":46,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-522"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}