{"success":true,"data":{"threats":[{"id":"764ad5c3-9268-4d77-acd6-ed9b2447fd3f","slug":"cve-2026-19498","externalId":"CVE-2026-19498","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19498 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to cause a denial…","description":"IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.","cveId":"CVE-2026-19498","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-674"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291628","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:57.480Z","addedAt":"2026-10-08T23:06:39.808Z","updatedAt":"2026-10-08T23:06:39.808Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19498","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19498","note":"authoritative record"}]},{"id":"367b24d8-2bd0-4cbe-a4ef-05d571bda638","slug":"cve-2026-107376","externalId":"CVE-2026-107376","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107376 — webonyx graphql-php is a PHP implementation of the GraphQL specification.","description":"webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\\Language\\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote attacker can submit deeply nested selection sets, object or list values, or list types that exhaust the PHP process stack during pre-validation parsing, before query validation and complexity controls run. The resulting SIGSEGV can terminate PHP-FPM workers or long-running Swoole, RoadRunner, ReactPHP, or CLI processes and cannot be caught by application-level exception handling. This issue is fixed in version 15.32.3.","cveId":"CVE-2026-107376","cvssScore":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/webonyx/graphql-php/commit/6c1d6009a0f7557f66753bcfd07badd15acf77f4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/webonyx/graphql-php/commit/7b7f2080ca5f7d5340a696fc5701b19a9222d2c2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/webonyx/graphql-php/releases/tag/v15.32.3","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/webonyx/graphql-php/security/advisories/GHSA-r7cg-qjjm-xhqq","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:22.373Z","addedAt":"2026-10-08T18:39:31.890Z","updatedAt":"2026-10-08T23:06:38.803Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107376","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107376","note":"authoritative record"}]},{"id":"4ccf69b5-0344-4796-b373-1bc11892e91d","slug":"ghsa-3c6w-j9xm-8h2h","externalId":"GHSA-3c6w-j9xm-8h2h","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion","description":"### Summary\n\nThe JSON response body processor parses response bodies with no recursion\nlimit. `ProcessResponse` calls `readJSON(ss, ignoreJSONRecursionLimit)`, and\nthat constant is `-1`. The guard in `readItems` only fires on `== 0`, so\ncounting down from `-1` (-2, -3, ...) never reaches it. The guard is effectively\ndead on the response path. The request path is fine: `ProcessRequest` passes the\nconfigured limit (default 1024). There is no equivalent directive or default for\nresponses.\n\nParsing a deeply nested JSON response is CPU-bound and its cost grows\nquadratically with nesting depth. A 512 KiB response (the default\n`ResponseBodyLimit`) holds about 87,000 nesting levels and takes ~12 s to\nprocess, keeping one core busy the whole time.\n\n### Root cause\n\n`internal/bodyprocessors/json.go`\n\n```go\nconst ignoreJSONRecursionLimit = -1                     // line 51\n\nfunc (js *jsonBodyProcessor) ProcessResponse(reader io.Reader, v ..., _ plugintypes.BodyProcessorOptions) error {\n    ...\n    data, err := readJSON(ss, ignoreJSONRecursionLimit) // line 62, passes -1\n}\n\nfunc (js *jsonBodyProcessor) ProcessRequest(...) error {\n    ...\n    data, err := readJSON(ss, bpo.RequestBodyRecursionLimit) // line 32, default 1024\n}\n```\n\nThe guard and the decrement:\n\n```go\nfunc readItems(json gjson.Result, objKey []byte, maxRecursion int, res map[string]string) error {\n    if maxRecursion == 0 {                              // line 106\n        return errors.New(\"max recursion reached while reading json object\")\n    }\n    ...\n    iterationError = readItems(value, objKey, maxRecursion-1, res) // line 126\n```\n\nNote that `ProcessResponse` discards `BodyProcessorOptions` (the parameter is\n`_`), so even a caller that wanted to set a limit on responses has no way to.\n\n### Why the cost is quadratic\n\nEvery nesting level re-parses the remaining nested document through\n`gjson.ForEach`, so total work is O(n²) in the depth. Numbers below were measured\non an Intel Core Ultra 7 255H, Go 1.22.2, gjson v1.18.0, at commit db9850b2\n(v3.7.0-55):\n\n```\ndepth   bytes    ProcessResponse time\n5000    30004    30 ms\n10000   60004    119 ms\n20000   120004   456 ms\n40000   240004   2.18 s\n87381   524290   12.09 s\n```\n\nLog-log slope between adjacent rows lands between 1.93 and 2.26 (2.09 across the\nfull range), which matches quadratic. Roughly 87,000 levels is the most that\nfits inside the default 512 KiB `ResponseBodyLimit`.\n\n### PoC\n\nSave as `internal/bodyprocessors/poc_json_test.go`, then:\n\n```\ngo test -v -timeout 120s -run TestPoCJSONResponse ./internal/bodyprocessors/...\n```\n\n```go\npackage bodyprocessors_test\n\nimport (\n      \"strings\"\n      \"testing\"\n      \"time\"\n\n      \"github.com/corazawaf/coraza/v3/experimental/plugins/plugintypes\"\n      \"github.com/corazawaf/coraza/v3/internal/bodyprocessors\"\n      \"github.com/corazawaf/coraza/v3/internal/corazawaf\"\n)\n\nfunc nestedJSON(depth int) string {\n      var sb strings.Builder\n      sb.Grow(depth*6 + 4)\n      for i := 0; i < depth; i++ {\n              sb.WriteString(`{\"a\":`)\n      }\n      sb.WriteString(\"null\")\n      for i := 0; i < depth; i++ {\n              sb.WriteByte('}')\n      }\n      return sb.String()\n}\n\nfunc TestPoCJSONResponse(t *testing.T) {\n      proc, _ := bodyprocessors.GetBodyProcessor(\"json\")\n\n      // Request path is bounded, response path is not.\n      body := nestedJSON(5000)\n      v := corazawaf.NewTransactionVariables()\n      errReq := proc.ProcessRequest(strings.NewReader(body), v,\n              plugintypes.BodyProcessorOptions{RequestBodyRecursionLimit: 1024})\n      errRes := proc.ProcessResponse(strings.NewReader(body), v,\n              plugintypes.BodyProcessorOptions{})\n      t.Logf(\"depth=5000 ProcessRequest  err=%v\", errReq)\n      t.Logf(\"depth=5000 ProcessResponse err=%v\", errRes)\n\n      // Quadratic scaling on the response path.\n      for _, depth := range []int{5000, 10000, 20000, 40000, 87381} {\n              b := nestedJSON(depth)\n              vv := corazawaf.NewTransactionVariables()\n              start := time.Now()\n              proc.ProcessResponse(strings.NewReader(b), vv,\n                      plugintypes.BodyProcessorOptions{})\n              t.Logf(\"depth=%-6d bytes=%-7d time=%v\", depth, len(b), time.Since(start))\n      }\n}\n```\n\nOutput on the reference machine:\n\n```\ndepth=5000 ProcessRequest  err=max recursion reached while reading json object\ndepth=5000 ProcessResponse err=<nil>\ndepth=5000   bytes=30004   time=30.3ms\ndepth=10000  bytes=60004   time=119.3ms\ndepth=20000  bytes=120004  time=456.1ms\ndepth=40000  bytes=240004  time=2.185s\ndepth=87381  bytes=524290  time=12.085s\n```\n\n### Impact\n\nThis needs `ResponseBodyAccess` turned on and a backend that returns JSON\n(`application/json`). Reflection endpoints, download APIs that serve\nuser-supplied content, and JSON error responses that echo back user input are\nall plausible ways to route a nested body back through the WAF.\n\nThe work happens in a single goroutine and is CPU-bound: the body is already in\nmemory, so there is no I/O during the parse. Each such request holds one core\nfor its entire run, about 12 s per 512 KiB body at the default limit. N\nconcurrent requests take N cores. The request path has enforced a recursion\nlimit since v3.3.3; responses never have.\n\n### Suggested fix\n\nBound `ProcessResponse` the same way the request path is bounded: add a\n`ResponseBodyRecursionLimit` directive, or just pass `RequestBodyRecursionLimit`\ninstead of `-1`.","cveId":null,"cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"Go","product":"github.com/corazawaf/coraza/v3","affectedVersions":["pkg:golang/github.com/corazawaf/coraza/v3 >= 3.0.0, < 3.8.0"],"cwes":["CWE-674"],"tags":["osv","osv:ghsa-3c6w-j9xm-8h2h","ecosystem:go"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-3c6w-j9xm-8h2h","type":"advisory","title":"OSV GHSA-3c6w-j9xm-8h2h"},{"url":"https://github.com/corazawaf/coraza/security/advisories/GHSA-3c6w-j9xm-8h2h","type":"other","title":"OSV web"},{"url":"https://github.com/corazawaf/coraza/commit/cae3c7407e7b84372c207033de03f15f89bf351a","type":"other","title":"OSV web"},{"url":"https://github.com/corazawaf/coraza","type":"vendor","title":"OSV package"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.8.0","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:51:42.000Z","addedAt":"2026-10-08T18:42:42.134Z","updatedAt":"2026-10-08T18:42:42.134Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-3c6w-j9xm-8h2h"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-3c6w-j9xm-8h2h"}]},{"id":"8d8c629b-f932-4b12-976c-1b4817e1853a","slug":"ghsa-6gcq-wc29-5xf2","externalId":"GHSA-6gcq-wc29-5xf2","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Coraza JSON body processor: argument-limit truncation reopens an unbounded-depth gjson.Valid stack overflow (process crash)","description":"### Summary\n\nThe JSON body processor (`internal/bodyprocessors/json.go`) can be made to\ncrash the whole process with an unrecoverable `fatal error: stack overflow`,\nusing a request body that is well under the recommended `SecRequestBodyLimit`\nand the default `SecArgumentsLimit`.\n\n### Root cause\n\n`readJSON` (json.go:113-143) runs a bounded, best-effort flattening walk\n(`readItems`) and *afterwards* calls `gjson.Valid(s)` on the raw body if\n`readItems` returned no error:\n\n```go\njson := gjson.Parse(s)\n...\ntruncated, err = readItems(json, key, maxRecursion, argumentLimit, byteBudget, &usedBytes, &argCount, res)\nif err != nil {\n    return res, truncated, err\n}\nif !gjson.Valid(s) {\n    return res, truncated, errors.New(\"invalid JSON\")\n}\n```\n\n`gjson.Valid` (gjson v1.18.0, `validany` -> `validarray`/`validobject`) recurses\nonce per nesting level with **no depth bound**. `readItems` does have a depth\nbound (`maxRecursion`), enforced here (json.go:163-182):\n\n```go\nfunc readItems(json gjson.Result, objKey []byte, maxRecursion int, argumentLimit int, byteBudget int, usedBytes *int, argCount *int, res map[string][]string) (truncated bool, err error) {\n    if byteBudget > 0 && *usedBytes >= byteBudget {\n        return true, nil                 // <-- checked first\n    }\n    if argumentLimit > 0 && *argCount >= argumentLimit {\n        return true, nil                 // <-- checked second\n    }\n    ...\n    if maxRecursion <= 0 {\n        return false, errors.New(\"max recursion reached while reading json object\")\n    }\n```\n\nThe byte-budget and argument-limit checks run *before* the recursion-depth\ncheck, and they short-circuit the walk with `truncated=true, err=nil` instead\nof recursing further. If the configured `SecArgumentsLimit`\n(`ArgumentLimit`, default 1000, `internal/corazawaf/waf.go:359`) is reached by\nearlier, shallow values in the document, `readItems` stops walking *before it\never reaches* a deeply nested tail later in the same document — so the\n`maxRecursion` error is never produced, `err` comes back `nil`, and `readJSON`\nfalls through to the unconditional `gjson.Valid(s)` call on the complete raw\nbody, including the part `readItems` never visited.\n\nThis is not a new interaction with the recursion limit itself: at v3.7.0,\n`gjson.Valid` ran unconditionally before any recursion check at all, so a\nplain deeply-nested body crashed the process directly. A later fix added a\ndepth check that returns an error before `Valid` runs for the *straightforward*\ncase (nesting reached before any other guard fires). The argument-limit /\nbyte-budget guards added since then (GHSA-6r3q-mjv7-xr8m,\nGHSA-3ww9-vw83-9w5x) reopened the same crash for the case above, because they\nshort-circuit the walk (and therefore the recursion counter) ahead of the\ndepth check, on both the request and response body path (`ProcessResponse`\ncalls the same `readJSON`, json.go:57-88).\n\nBecause this is `fatal error: stack overflow`, not a `panic`, it is **not**\nrecoverable by any `recover()` in the calling goroutine — the process\nterminates unconditionally.\n\n### PoC\n\n```go\npackage bodyprocessors\n\nimport (\n    \"strings\"\n    \"testing\"\n)\n\nfunc TestStackOverflowRepro(t *testing.T) {\n    body := \"[\" + strings.Repeat(\"1,\", 1000) + strings.Repeat(\"[\", 13_000_000)\n    // 13,002,001 bytes total: under the recommended SecRequestBodyLimit\n    // (13107200, coraza.conf-recommended:78) and default ArgumentLimit (1000,\n    // internal/corazawaf/waf.go:359).\n    _, _, _ = readJSON(body, 20, 1000)\n}\n```\n\n```\n$ go test -run TestStackOverflowRepro ./internal/bodyprocessors/ -v\nruntime: goroutine stack exceeds 1000000000-byte limit\nfatal error: stack overflow\n...\ngithub.com/tidwall/gjson.validarray(...)\n\t.../gjson@v1.18.0/gjson.go:2584\ngithub.com/tidwall/gjson.validany(...)\n\t.../gjson@v1.18.0/gjson.go:2499\ngithub.com/tidwall/gjson.validarray(...)\n\t.../gjson@v1.18.0/gjson.go:2589\n... (repeats until the goroutine stack limit is hit)\n```\n\nReproduced against commit `19b86824` (tag `v3.8.0`), both by calling\n`readJSON` directly and end-to-end through the recommended\n`coraza.conf-recommended` configuration (JSON `Content-Type`, default\n`SecArgumentsLimit`, recommended `SecRequestBodyLimit`).\n\n### Impact\n\nAn unauthenticated attacker who can send an HTTP request body (any endpoint\nprotected by Coraza with the JSON body processor enabled, which is the\ndefault for `application/json`) can crash the entire host process with a\nsingle request, using a payload well within default and recommended body\nsize and argument-count limits. There is no privilege or interaction\nrequirement, and the crash cannot be caught or mitigated by the integrator\n(no `recover()` stops a stack-overflow fatal error). This is strictly worse\nthan a CPU-exhaustion or slow-request DoS: the process must be restarted, and\nevery in-flight request/transaction on that process is lost.\n\n### Suggested fix\n\nRun an iterative, explicitly-bounded-depth pre-scan (or reuse `readItems`'s\nown recursion accounting) before calling `gjson.Valid`, and never call\n`gjson.Valid` on input whose nesting exceeds `maxRecursion`. The response\npath (`ProcessResponse`) needs the same treatment since it shares `readJSON`.\n\n### AI involvement disclosure\n\n- **AI tools/models used:** Claude Sonnet 5 (Anthropic), via Claude Code.\n- **What was generated/assisted:** the initial vulnerability hypothesis and\n  repro shape were supplied by the reporter as an existing written finding;\n  Claude Sonnet 5 independently re-derived the root cause by reading the\n  current source, wrote and ran a fresh PoC test against commit `19b86824`\n  (tag `v3.8.0`), confirmed the crash and stack trace shown above, verified\n  the default configuration values cited (`ArgumentLimit` default,\n  `SecRequestBodyLimit` recommended value) against the current source, and\n  drafted this advisory text.\n- **Review performed:** reproduced by hand by running the PoC test above with\n  `go test -run TestStackOverflowRepro ./internal/bodyprocessors/ -v` against\n  a clean checkout of commit `19b86824`; observed the `fatal error: stack\n  overflow` and stack trace through `gjson.validarray`/`validany`; traced\n  `readJSON`/`readItems` line by line to confirm the guard ordering described\n  above; the PoC was reviewed by a human maintainer (fzipi) before\n  submission of this advisory.","cveId":null,"cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"Go","product":"github.com/corazawaf/coraza/v3","affectedVersions":["pkg:golang/github.com/corazawaf/coraza/v3 >= 3.0.0, < 3.8.1"],"cwes":["CWE-674"],"tags":["osv","osv:ghsa-6gcq-wc29-5xf2","ecosystem:go"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-6gcq-wc29-5xf2","type":"advisory","title":"OSV GHSA-6gcq-wc29-5xf2"},{"url":"https://github.com/corazawaf/coraza/security/advisories/GHSA-6gcq-wc29-5xf2","type":"other","title":"OSV web"},{"url":"https://github.com/corazawaf/coraza/commit/814e1898e083d2ff2ceb644382d0da17e930f93f","type":"other","title":"OSV web"},{"url":"https://github.com/corazawaf/coraza","type":"vendor","title":"OSV package"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.8.1","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:45:46.000Z","addedAt":"2026-10-08T18:42:42.076Z","updatedAt":"2026-10-08T18:42:42.076Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-6gcq-wc29-5xf2"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-6gcq-wc29-5xf2"}]},{"id":"fb8cf4cf-9165-40f5-8348-b258e4da2e57","slug":"cve-2026-107300","externalId":"CVE-2026-107300","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107300 — msgpack5 is a msgpack v5 implementation for node.js and the browser.","description":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.","cveId":"CVE-2026-107300","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"npm","product":"msgpack5","affectedVersions":["pkg:npm/msgpack5 < 6.1.0"],"cwes":["CWE-674"],"tags":["nvd","status:received","osv","osv:ghsa-5x5g-h9x8-2fh9","ecosystem:npm","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mcollina/msgpack5/commit/77fbef144d05def5d16fc22c37caa64c0a7efeba","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-5x5g-h9x8-2fh9","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-5x5g-h9x8-2fh9","type":"advisory","title":"OSV GHSA-5x5g-h9x8-2fh9"},{"url":"https://github.com/mcollina/msgpack5","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:16.000Z","addedAt":"2026-10-08T18:39:31.752Z","updatedAt":"2026-10-08T21:05:51.450Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107300","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107300","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-5X5G-H9X8-2FH9"}]},{"id":"617ee614-85b3-4e60-a2bb-82bd13592aa9","slug":"cve-2026-107298","externalId":"CVE-2026-107298","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107298 — msgpack5 is a msgpack v5 implementation for node.js and the browser.","description":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers that exhaust the JavaScript call stack and interrupt a process, worker, or request handler. This issue is fixed in version 6.1.0.","cveId":"CVE-2026-107298","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":"npm","product":"msgpack5","affectedVersions":["pkg:npm/msgpack5 < 6.1.0"],"cwes":["CWE-674"],"tags":["nvd","status:received","osv","osv:ghsa-24ch-f2g6-9hhh","ecosystem:npm","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mcollina/msgpack5/commit/1e2b5874e555dd7c99417f64788a03b0590bb102","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-24ch-f2g6-9hhh","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-24ch-f2g6-9hhh","type":"advisory","title":"OSV GHSA-24ch-f2g6-9hhh"},{"url":"https://github.com/mcollina/msgpack5","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:15.703Z","addedAt":"2026-10-08T18:39:31.738Z","updatedAt":"2026-10-08T21:05:51.305Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107298","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107298","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-24CH-F2G6-9HHH"}]},{"id":"ffd5d5c6-0831-4e43-95c1-090cf6b190af","slug":"cve-2026-107678","externalId":"CVE-2026-107678","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107678 — FFmpeg through 9.0.2 contains a stack exhaustion vulnerability in av_encryption_init_info_free() in libavutil/encryption_info.c, which recursively …","description":"FFmpeg through 9.0.2 contains a stack exhaustion vulnerability in av_encryption_init_info_free() in libavutil/encryption_info.c, which recursively frees AVEncryptionInitInfo linked lists built by the MOV demuxer's mov_read_pssh(). Attackers can supply a crafted MP4 file with tens of thousands of small pssh boxes to exhaust the stack and crash the process, while also causing quadratic CPU consumption.","cveId":"CVE-2026-107678","cvssScore":5.7,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24593","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://ffmpeg.org/","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavformat/mov.c#L8070","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavutil/encryption_info.c#L219-L231","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-stack-exhaustion-via-recursive-free-of-pssh-boxes","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:17:05.747Z","addedAt":"2026-10-08T16:39:36.064Z","updatedAt":"2026-10-08T23:06:38.464Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107678","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107678","note":"authoritative record"}]},{"id":"c68c2958-1a78-41bb-ac0a-e83511ca7e69","slug":"cve-2026-105827","externalId":"CVE-2026-105827","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105827 — ImageMagick before 7.1.2-30 and 6.9.13-55 contains an uncontrolled recursion vulnerability in the CALS decoder due to a missing depth check.","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains an uncontrolled recursion vulnerability in the CALS decoder due to a missing depth check. Attackers can supply a crafted CALS image that triggers unbounded recursion, exhausting the stack and crashing the process, resulting in a denial of service.","cveId":"CVE-2026-105827","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wxw6-98rj-hjfr","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-stack-overflow-in-cals-decoder","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:34.820Z","addedAt":"2026-10-08T16:39:35.679Z","updatedAt":"2026-10-08T21:05:49.966Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105827","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105827","note":"authoritative record"}]},{"id":"54807cb1-2136-4900-8c67-03704e35eef2","slug":"cve-2026-44037","externalId":"CVE-2026-44037","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-44037 — Uncontrolled mutual recursion between DcmJSONReader::parseDataSet(), DcmJSONReader::parseElement() and DcmJSONReader::parseSequence() in dcmdata/li…","description":"Uncontrolled mutual recursion between DcmJSONReader::parseDataSet(), DcmJSONReader::parseElement() and DcmJSONReader::parseSequence() in dcmdata/libsrc/dcjsonrd.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOM JSON document with deeply nested sequence (SQ) values. The json2dcm tool and any service that converts untrusted DICOM JSON (for example, DICOMweb payloads) with this reader are affected. The issue is fixed in commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7.","cveId":"CVE-2026-44037","cvssScore":6.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/DCMTK/dcmtk/commit/cf955e64c35a1e07ba10698f639d5dcdec53b9d7","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"},{"url":"https://support.dcmtk.org/redmine/issues/1225","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:17.817Z","addedAt":"2026-10-08T14:40:02.731Z","updatedAt":"2026-10-08T23:06:38.010Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44037","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-44037","note":"authoritative record"}]},{"id":"7a72f829-302b-4ffd-aca9-34e7f9f4c09a","slug":"cve-2026-44036","externalId":"CVE-2026-44036","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-44036 — Uncontrolled mutual recursion between DcmXMLParseHelper::parseDataSet() and DcmXMLParseHelper::parseSequence() in the XML-to-DICOM converter (dcmda…","description":"Uncontrolled mutual recursion between DcmXMLParseHelper::parseDataSet() and DcmXMLParseHelper::parseSequence() in the XML-to-DICOM converter (dcmdata/libdcxml/xml2dcm.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML file with deeply nested sequence and item elements. The xml2dcm tool and any service that converts untrusted XML to DICOM with this code are affected. The issue is fixed in commit 87f256d73e30656a822bf7d76d1cf1d9bb693954.","cveId":"CVE-2026-44036","cvssScore":6.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/DCMTK/dcmtk/commit/87f256d73e30656a822bf7d76d1cf1d9bb693954","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"},{"url":"https://support.dcmtk.org/redmine/issues/1224","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:17.653Z","addedAt":"2026-10-08T14:40:02.722Z","updatedAt":"2026-10-08T23:06:37.988Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44036","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-44036","note":"authoritative record"}]},{"id":"3f890388-02d2-487e-bf2f-20f37d0e2a67","slug":"cve-2026-44035","externalId":"CVE-2026-44035","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-44035 — Uncontrolled recursion in DcmDicomDir::moveRecordToTree() in dcmdata/libsrc/dcdicdir.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial o…","description":"Uncontrolled recursion in DcmDicomDir::moveRecordToTree() in dcmdata/libsrc/dcdicdir.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOMDIR file with a deeply chained sequence of directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute. Any application that opens the DICOMDIR is affected, including dcmgpdir and media viewers built on DCMTK. The issue is fixed in commit ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f.","cveId":"CVE-2026-44035","cvssScore":6.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/DCMTK/dcmtk/commit/ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"},{"url":"https://support.dcmtk.org/redmine/issues/1215","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:17.497Z","addedAt":"2026-10-08T14:40:02.715Z","updatedAt":"2026-10-08T23:06:37.971Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44035","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-44035","note":"authoritative record"}]},{"id":"c7d966fb-d432-414a-baa4-7c657d119388","slug":"cve-2026-44033","externalId":"CVE-2026-44033","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-44033 — Uncontrolled recursion in XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() in the bundled XML parser (ofstd/libsrc/ofxml.cc) of OFFIS DCMTK 3…","description":"Uncontrolled recursion in XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() in the bundled XML parser (ofstd/libsrc/ofxml.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML document with deeply nested elements. The parser is reachable through dcmencap when encapsulating a CDA document, and through any application that calls OFXMLParser::parseFile() or OFXMLParser::parseString() on untrusted input. The issue is fixed in commit d12e350e687530eb41e2b0c860aff4d8c04e5941.","cveId":"CVE-2026-44033","cvssScore":6.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/DCMTK/dcmtk/commit/d12e350e687530eb41e2b0c860aff4d8c04e5941","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"},{"url":"https://support.dcmtk.org/redmine/issues/1214","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:17.197Z","addedAt":"2026-10-08T14:40:02.699Z","updatedAt":"2026-10-08T23:06:37.915Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44033","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-44033","note":"authoritative record"}]},{"id":"afba258c-db7a-44ee-b761-e600f859ae85","slug":"cve-2026-44031","externalId":"CVE-2026-44031","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-44031 — Uncontrolled recursion in DcmSequenceOfItems::read() and DcmItem::read() in the dcmdata library of OFFIS DCMTK 3.7.0 allows a remote, unauthenticat…","description":"Uncontrolled recursion in DcmSequenceOfItems::read() and DcmItem::read() in the dcmdata library of OFFIS DCMTK 3.7.0 allows a remote, unauthenticated attacker to cause a denial of service (stack exhaustion and process crash) via a DICOM dataset containing deeply nested sequences (SQ elements). The dataset can be sent in a C-STORE request to storescp, dcmrecv, dcmqrscp, or any other DICOM service built on DCMTK, because the received dataset is parsed before any authentication takes place. Local tools such as dcmdump also crash when opening such a file. The issue is fixed in commit 885ff0f10372bd589b5f44cea974f28a3964cb0f, which adds a configurable sequence nesting depth limit (default 64).","cveId":"CVE-2026-44031","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/DCMTK/dcmtk/commit/885ff0f10372bd589b5f44cea974f28a3964cb0f","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"},{"url":"https://support.dcmtk.org/redmine/issues/1191","type":"advisory","title":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T13:17:17.027Z","addedAt":"2026-10-08T14:40:02.691Z","updatedAt":"2026-10-08T23:06:37.891Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44031","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-44031","note":"authoritative record"}]},{"id":"43bd5a56-e794-4a0c-8d1a-33104bc029dd","slug":"cve-2026-107216","externalId":"CVE-2026-107216","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107216 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calculation context at each cycle and bypassing in-flight and iteration controls. ANCHORARRAY calls CalcCellValue instead of cellResolver, so each recursive hop receives a new calcContext and loses cycle state. When mutually referencing dynamic-array formulas are evaluated directly or through formula-evaluating APIs, each recursion hop resets the cycle budget and prevents completion-based caches from breaking the cycle, allowing an attacker to cause a fatal Go stack overflow and abort the process. No fixed version is available as of this review.","cveId":"CVE-2026-107216","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.8.1, < 2.11.1-0.20260911060113-ea12859e43c6"],"cwes":["CWE-674"],"tags":["nvd","status:received","osv","osv:ghsa-wp2g-vpjj-g53r","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/ea12859e43c64d498ecf839263c5f917391f3316","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-wp2g-vpjj-g53r","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-wp2g-vpjj-g53r","type":"advisory","title":"OSV GHSA-wp2g-vpjj-g53r"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107216","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00311,"epssPercentile":0.21969,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T18:17:19.400Z","addedAt":"2026-10-07T18:39:31.700Z","updatedAt":"2026-10-08T21:05:43.437Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107216","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107216","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-WP2G-VPJJ-G53R"}]},{"id":"16271630-358f-45ad-88d9-a698f832b51f","slug":"cve-2026-107208","externalId":"CVE-2026-107208","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107208 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted XMP profile can reach a recursion limit that is handled as a fatal condition instead of an ordinary exception, terminating the image-processing process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.","cveId":"CVE-2026-107208","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400","CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/907b74817836b4f88e7453f0e95c849a1c5311aa","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-27m9-54jx-fgvq","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/commit/6ba345f88a14fcce35c723c231914ae054c4281a","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00302,"epssPercentile":0.20994,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:45.773Z","addedAt":"2026-10-07T16:39:32.706Z","updatedAt":"2026-10-08T21:05:42.303Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107208","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107208","note":"authoritative record"}]},{"id":"04121609-52ed-4b1f-bff0-9a10d05b895a","slug":"cve-2026-106572","externalId":"CVE-2026-106572","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106572 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a missing recursion-depth check in the CALS decoder allows a crafted CALS image to exhaust the call stack and terminate the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.","cveId":"CVE-2026-106572","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/19bce64e3667ff03","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wxw6-98rj-hjfr","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/commit/0ca580238abba18910cfee0fcc3159621fec0dee","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00384,"epssPercentile":0.30341,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:43.070Z","addedAt":"2026-10-07T16:39:32.600Z","updatedAt":"2026-10-08T21:05:42.074Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106572","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106572","note":"authoritative record"}]},{"id":"046b46ae-a75d-4bb1-b821-3e32f2e4cb10","slug":"cve-2026-106449","externalId":"CVE-2026-106449","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106449 — yawkat LZ4 Java provides LZ4 compression for Java.","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4.","cveId":"CVE-2026-106449","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"low","vendor":"Maven","product":"at.yawk.lz4:lz4-java","affectedVersions":["pkg:maven/at.yawk.lz4/lz4-java < 1.11.4","pkg:maven/org.lz4/lz4-java <= 1.8.1"],"cwes":["CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-343h-94h5-c4wr","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","type":"other","title":"OSV web"},{"url":"https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-343h-94h5-c4wr","type":"advisory","title":"OSV GHSA-343h-94h5-c4wr"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106449","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/yawkat/lz4-java","type":"vendor","title":"OSV package"}],"epssScore":0.00339,"epssPercentile":0.25225,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:26.887Z","addedAt":"2026-10-06T20:39:33.082Z","updatedAt":"2026-10-08T00:42:49.798Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106449","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106449","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-343H-94H5-C4WR"}]},{"id":"693c9c3b-5c6a-42a9-b587-af0dabf16003","slug":"cve-2026-106447","externalId":"CVE-2026-106447","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106447 — StableLib is a stable library of useful TypeScript and JavaScript code.","description":"StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor decoder recursively processes nested CBOR arrays, maps, and tags through _decodeValue() without enforcing a maximum nesting depth. A sufficiently deep structure exhausts the JavaScript call stack, causing a decoding exception and potentially terminating an uncaught request worker or process. This issue is fixed in version 2.0.4.","cveId":"CVE-2026-106447","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"npm","product":"@stablelib/cbor","affectedVersions":["pkg:npm/%40stablelib/cbor < 2.0.3"],"cwes":["CWE-674"],"tags":["nvd","status:received","osv","osv:ghsa-5jg4-p4qw-cgfr","ecosystem:npm","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/StableLib/stablelib/commit/0149e18d9d4736e22c257744ca945ebce7899a01","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/StableLib/stablelib/releases/tag/@stablelib/cbor@2.0.4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/StableLib/stablelib/security/advisories/GHSA-5jg4-p4qw-cgfr","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-5jg4-p4qw-cgfr","type":"advisory","title":"OSV GHSA-5jg4-p4qw-cgfr"},{"url":"https://github.com/StableLib/stablelib","type":"vendor","title":"OSV package"}],"epssScore":0.00371,"epssPercentile":0.28982,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:26.573Z","addedAt":"2026-10-06T20:39:33.066Z","updatedAt":"2026-10-07T16:39:30.847Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106447","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106447","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-5JG4-P4QW-CGFR"}]},{"id":"52199794-4de8-40d8-b04c-6f365cfdf5e4","slug":"cve-2026-103008","externalId":"CVE-2026-103008","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103008 — Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes the server to construct…","description":"Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes the server to construct and process a deeply nested data structure with no bound on recursion depth. Elasticsearch contains an uncontrolled recursion weakness in how it builds and serializes geometry values produced by scripted runtime fields. Unlike geometry supplied as text, which is subject to a nesting-depth limit, geometry constructed from a script's output is not bounded. An authenticated user with read access to a single index can submit a request defining such a field with a script that produces a deeply nested structure. Processing this request recurses past the available stack space, causing the affected node to terminate. The node does not recover automatically on all deployments and may require manual intervention to restore service.","cveId":"CVE-2026-103008","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://discuss.elastic.co/t/elasticsearch-8-19-23-9-4-8-9-5-5-security-update-esa-2026-198/390872","type":"advisory","title":"security@elastic.co"}],"epssScore":0.00302,"epssPercentile":0.21055,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:14.120Z","addedAt":"2026-10-06T20:39:32.891Z","updatedAt":"2026-10-07T14:39:34.049Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103008","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103008","note":"authoritative record"}]},{"id":"ad9514f7-5837-44fa-8717-9ac7232edf5e","slug":"cve-2026-103006","externalId":"CVE-2026-103006","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103006 — Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the agg…","description":"Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API. Elasticsearch contains an uncontrolled recursion weakness in its search aggregation processing. An authenticated user with read access to a single index can submit a specially crafted request containing deeply nested aggregation definitions. Processing this request triggers unbounded recursive execution that exhausts the server process's available resources, causing the affected node to terminate. The node does not recover automatically and requires manual intervention to restore service.","cveId":"CVE-2026-103006","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-674"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://discuss.elastic.co/t/elasticsearch-8-19-21-9-4-6-9-5-2-security-update-esa-2026-196/390870","type":"advisory","title":"security@elastic.co"}],"epssScore":0.00401,"epssPercentile":0.32223,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:13.730Z","addedAt":"2026-10-06T20:39:32.874Z","updatedAt":"2026-10-07T14:39:34.033Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103006","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103006","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":220,"totalPages":11,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T00:25:36.161Z","durationMs":22,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-674"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}