{"success":true,"data":{"threats":[{"id":"ce7c4d80-9446-4068-99e4-1fd3ae3e3ee0","slug":"cve-2026-106432","externalId":"CVE-2026-106432","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106432 — The BSON encoder in the MongoDB PHP Driver converts a string length to a 32-bit value without validation.","description":"The BSON encoder in the MongoDB PHP Driver converts a string length to a 32-bit value without validation. When an affected application encodes a string near 4 GiB, the allocation size can wrap while the copy operation uses the original length. The resulting heap buffer overflow can corrupt process memory or terminate the PHP process. Reaching this issue requires a non-default runtime configuration that permits multi-gigabyte values. No MongoDB server interaction is required.","cveId":"CVE-2026-106432","cvssScore":2,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-681"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://jira.mongodb.org/browse/PHPC-2741","type":"advisory","title":"cna@mongodb.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:30.647Z","addedAt":"2026-10-08T21:05:52.817Z","updatedAt":"2026-10-08T21:05:52.817Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106432","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106432","note":"authoritative record"}]},{"id":"a6d8e418-82b2-46e1-8c6f-b16cfa4ae3ed","slug":"cve-2026-107224","externalId":"CVE-2026-107224","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107224 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.","description":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, a Zip64 uncompressed size with the high bit set is converted from uint64 to a negative int64 before signed size-limit checks and allocation. ReadZipReader obtains UncompressedSize64 through FileInfo.Size and passes the wrapped negative value to readFile. When a crafted Zip64 entry declares an uncompressed size from 2^63 through 2^64-1 and the workbook is opened, the negative size bypasses unzip limits and reaches make as a negative capacity, allowing an attacker to panic during workbook opening. No fixed version is available as of this review.","cveId":"CVE-2026-107224","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":"Go","product":"github.com/xuri/excelize/v2","affectedVersions":["pkg:golang/github.com/xuri/excelize/v2 >= 2.1.0, < 2.11.1-0.20260805032953-db93f8d89de7"],"cwes":["CWE-190","CWE-681"],"tags":["nvd","status:received","osv","osv:ghsa-fw94-4wwp-w8pw","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/qax-os/excelize/commit/db93f8d89de71589069a54d1b998af02e3c5f7cd","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2369","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-fw94-4wwp-w8pw","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-fw94-4wwp-w8pw","type":"advisory","title":"OSV GHSA-fw94-4wwp-w8pw"},{"url":"https://github.com/qax-os/excelize","type":"vendor","title":"OSV package"}],"epssScore":0.00356,"epssPercentile":0.2731,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T19:17:35.140Z","addedAt":"2026-10-07T20:39:40.439Z","updatedAt":"2026-10-08T21:05:43.717Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107224","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107224","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-FW94-4WWP-W8PW"}]},{"id":"e77dea02-51e3-4613-9a03-cf3775af56d7","slug":"cve-2026-47539","externalId":"CVE-2026-47539","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-47539 — NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect numeric conv…","description":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect numeric conversion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cveId":"CVE-2026-47539","cvssScore":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-681"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5861","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47539","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47539","type":"advisory","title":"psirt@nvidia.com"}],"epssScore":0.00132,"epssPercentile":0.02395,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:17:21.143Z","addedAt":"2026-09-30T17:50:48.053Z","updatedAt":"2026-10-01T05:50:42.777Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47539","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-47539","note":"authoritative record"}]},{"id":"a7bd0a7d-6822-4a84-b268-de162e32abe7","slug":"cve-2026-47508","externalId":"CVE-2026-47508","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-47508 — NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an incorrect conversion…","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an incorrect conversion between numeric types. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cveId":"CVE-2026-47508","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-681"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5861","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47508","type":"advisory","title":"psirt@nvidia.com"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47508","type":"advisory","title":"psirt@nvidia.com"}],"epssScore":0.00146,"epssPercentile":0.03338,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:17:16.110Z","addedAt":"2026-09-30T17:50:47.894Z","updatedAt":"2026-10-01T05:50:42.611Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47508","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-47508","note":"authoritative record"}]},{"id":"026a115d-fe6a-4a15-900e-88b15397b839","slug":"cve-2026-98049","externalId":"CVE-2026-98049","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-98049 — In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: zero extend the result of an arena 32-bit cmpxchg\n\nbpf_convert_ctx_access…","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: zero extend the result of an arena 32-bit cmpxchg\n\nbpf_convert_ctx_accesses() rewrites an atomic on an arena pointer from\nBPF_STX | BPF_ATOMIC to BPF_STX | BPF_PROBE_ATOMIC, and it runs before\nbpf_opt_subreg_zext_lo32_rnd_hi32().\n\nThat pass emits an explicit zero extension for a 32-bit cmpxchg even\nwhen bpf_jit_needs_zext() is false. This is done because on some\narchitectures 32-bit cmpxchg requires explicit zero extension for the\ndst register. E.g. on x86-64 'lock cmpxchg' does not change the %eax\nif comparison is successful, while BPF semantics declare that each\noperation on a 32-bit register zero extends it's upper half.\n\nis_cmpxchg_insn() matches BPF_MODE == BPF_ATOMIC only, so an arena\ncmpxchg misses said zero extension adjustment. This patch adjusts\nis_cmpxchg_insn() to match BPF_PROBE_ATOMIC alongside BPF_ATOMIC.","cveId":"CVE-2026-98049","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"linux","product":"linux kernel","affectedVersions":[">= 6.10, < 7.2.7","7.3"],"cwes":["CWE-681"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://git.kernel.org/stable/c/1c1b476d43a8b6c9bc04600369dd8cc39950d98e","https://git.kernel.org/stable/c/4814ed6406f3493bd554ad046da5f7fc04833571"],"references":[{"url":"https://git.kernel.org/stable/c/1c1b476d43a8b6c9bc04600369dd8cc39950d98e","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/4814ed6406f3493bd554ad046da5f7fc04833571","type":"patch","title":"Patch"}],"epssScore":0.00107,"epssPercentile":0.01084,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-25T11:17:33.770Z","addedAt":"2026-09-25T11:50:39.490Z","updatedAt":"2026-10-06T13:50:41.209Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98049","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-98049","note":"authoritative record"}]},{"id":"638aadc4-8a14-48dc-b106-ef9544420cfa","slug":"cve-2026-88387","externalId":"CVE-2026-88387","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88387 — LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType).","description":"LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, TIFF, or DNG file can supply an attacker-controlled NewSubfileType value outside the range of a signed int. The parser converts this value and narrows it to int without performing range validation. This out-of-range conversion triggers undefined behavior, resulting in process termination and denial of service.","cveId":"CVE-2026-88387","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-681"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/LibRaw/LibRaw/commit/b41cbbd61951783e0440590dae55411a16185bdf","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/LibRaw/LibRaw/issues/844","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/LibRaw/LibRaw/pull/853","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00118,"epssPercentile":0.01572,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T21:18:57.120Z","addedAt":"2026-09-24T21:50:44.812Z","updatedAt":"2026-09-29T03:50:38.539Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88387","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88387","note":"authoritative record"}]},{"id":"7515c4e2-772d-4d75-b4d1-3206807d3fd3","slug":"cve-2026-88367","externalId":"CVE-2026-88367","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88367 — NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization.","description":"NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization. A specially crafted SVG document containing an extremely large stroke-width can cause floating-point rounding to produce a zero subdivision angle. The subsequent arc division yields infinity, which is converted to int without range validation, resulting in undefined behavior and process termination, leading to denial of service.","cveId":"CVE-2026-88367","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-681"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/memononen/nanosvg/issues/293","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00245,"epssPercentile":0.14493,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T17:17:06.973Z","addedAt":"2026-09-24T17:50:40.143Z","updatedAt":"2026-09-25T19:50:39.305Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88367","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88367","note":"authoritative record"}]},{"id":"af985480-ef71-4772-aa83-8508e4e5ce70","slug":"cve-2026-88368","externalId":"CVE-2026-88368","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88368 — NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() function.","description":"NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() function. A specially crafted SVG document containing sufficiently large geometry coordinates can cause fixed-point-scaled edge coordinates to exceed the range representable by int. The rasterizer subsequently converts these values to int without range validation, resulting in undefined behavior and possible process termination, leading to denial of service.","cveId":"CVE-2026-88368","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-681"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/memononen/nanosvg/issues/292","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.0039,"epssPercentile":0.30956,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T16:17:13.730Z","addedAt":"2026-09-24T17:50:39.553Z","updatedAt":"2026-09-24T21:50:44.375Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88368","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88368","note":"authoritative record"}]},{"id":"3e386d52-e8db-4cd1-a2eb-d7868a1dbd63","slug":"cve-2026-88366","externalId":"CVE-2026-88366","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88366 — NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG arc commands.","description":"NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG arc commands. A specially crafted SVG document containing extreme arc radius values can cause intermediate arc calculations to produce a NaN delta angle. The function subsequently converts this NaN value to int without validating that it is finite and representable, resulting in undefined behavior and process termination, leading to denial of service.","cveId":"CVE-2026-88366","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-681"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/memononen/nanosvg/issues/294","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00338,"epssPercentile":0.25205,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T16:17:13.607Z","addedAt":"2026-09-24T17:50:39.548Z","updatedAt":"2026-10-06T18:39:26.323Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88366","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88366","note":"authoritative record"}]},{"id":"7de2d9e0-17de-4c5f-b500-16f12c1f1ffc","slug":"cve-2026-88362","externalId":"CVE-2026-88362","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88362 — MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c.","description":"MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted JavaScript input containing an excessively large numeric array index can cause an out-of-range floating-point value to be converted to an integer without proper range validation. This results in undefined behavior and can cause process termination, leading to denial of service.","cveId":"CVE-2026-88362","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-681"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugs.ghostscript.com/show_bug.cgi?id=709636","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mujs.git/commit/?id=8a32c397b28fe45747ac4e9e4f3dca049825eda7","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00343,"epssPercentile":0.25783,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T16:17:13.350Z","addedAt":"2026-09-24T17:50:39.537Z","updatedAt":"2026-09-25T17:50:39.212Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88362","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88362","note":"authoritative record"}]},{"id":"80513845-58ed-4b7b-be9a-98a7e983ab62","slug":"cve-2026-77412","externalId":"CVE-2026-77412","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-77412 — RabbitMQ amqp091-go is a Go AMQP 0.9.1 client.","description":"RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-array field with type tag x into a signed int32 and passes the value directly to make when allocating the field buffer. A malicious or compromised broker can encode a value such as 0xFFFFFFFF, which becomes -1 and causes a len out of range runtime panic. The panic escapes the network reader goroutine and terminates the client process, including during connection.start server properties or message header table parsing. This issue is fixed in version 1.13.0.","cveId":"CVE-2026-77412","cvssScore":8.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"Go","product":"github.com/rabbitmq/amqp091-go","affectedVersions":["pkg:golang/github.com/rabbitmq/amqp091-go < 1.13.0"],"cwes":["CWE-681"],"tags":["nvd","status:received","osv","osv:ghsa-4v58-74mf-rjx3","ecosystem:go","status:awaiting-analysis","osv:go-2026-6494"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/rabbitmq/amqp091-go/commit/669b42bf7b1db76bc6d4973e3634247f680accbf","https://github.com/rabbitmq/amqp091-go/pull/344"],"references":[{"url":"https://github.com/rabbitmq/amqp091-go/commit/669b42bf7b1db76bc6d4973e3634247f680accbf","type":"patch","title":"OSV fix"},{"url":"https://github.com/rabbitmq/amqp091-go/pull/344","type":"patch","title":"OSV fix"},{"url":"https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0","type":"other","title":"OSV web"},{"url":"https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-4v58-74mf-rjx3","type":"advisory","title":"OSV advisory"},{"url":"https://osv.dev/vulnerability/GHSA-4v58-74mf-rjx3","type":"advisory","title":"OSV GHSA-4v58-74mf-rjx3"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77412","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/rabbitmq/amqp091-go","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/GO-2026-6494","type":"advisory","title":"OSV GO-2026-6494"}],"epssScore":0.00524,"epssPercentile":0.42604,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T15:17:50.707Z","addedAt":"2026-09-16T15:50:43.698Z","updatedAt":"2026-10-02T01:54:32.145Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77412","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-77412","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-4V58-74MF-RJX3"}]},{"id":"f24e364c-6a75-416e-99d9-8e1f9adc3258","slug":"cve-2026-69438","externalId":"CVE-2026-69438","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-69438 — Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network.","description":"Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network.","cveId":"CVE-2026-69438","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"microsoft","product":"windows 10 1607","affectedVersions":["< 10.0.14393.9512","< 10.0.17763.9245","< 10.0.19044.7725","< 10.0.19045.7725","< 10.0.22631.7582","< 10.0.26100.9445","< 10.0.26200.9445","< 10.0.28000.2954","r2","< 10.0.20348.5622","< 10.0.26100.33438"],"cwes":["CWE-681"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69438"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69438","type":"patch","title":"Patch"}],"epssScore":0.00707,"epssPercentile":0.51999,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T18:19:07.777Z","addedAt":"2026-09-08T19:50:39.801Z","updatedAt":"2026-09-29T15:50:40.442Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69438","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-69438","note":"authoritative record"}]},{"id":"72a50605-9829-432c-bf13-8015d30a30e6","slug":"cve-2026-84966","externalId":"CVE-2026-84966","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84966 — An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted i…","description":"An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field name to the builder, the library may read memory outside the intended buffer and terminate the calling process. No authentication is required, but the calling application must pass the oversized name in a specific form.","cveId":"CVE-2026-84966","cvssScore":5.9,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"mongodb","product":"c++ driver","affectedVersions":[">= 3.0.0, < 4.5.2"],"cwes":["CWE-681"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://jira.mongodb.org/browse/CXX-3548","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00142,"epssPercentile":0.03057,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-03T16:18:25.563Z","addedAt":"2026-09-03T17:50:35.651Z","updatedAt":"2026-09-22T17:50:41.479Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84966","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84966","note":"authoritative record"}]},{"id":"6e5001a3-1e16-485c-976c-f20b912766d5","slug":"cve-2026-84963","externalId":"CVE-2026-84963","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84963 — An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be …","description":"An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports success and returns no error. An unauthenticated party who can supply the input processed by an application that uses this component may cause that application to hold data that does not match what was submitted, which may result in unintended alteration of data.","cveId":"CVE-2026-84963","cvssScore":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"mongodb","product":"c driver","affectedVersions":[">= 1.10.0, < 1.30.9",">= 2.0.0, < 2.5.2"],"cwes":["CWE-681"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://jira.mongodb.org/browse/CDRIVER-6407","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.0031,"epssPercentile":0.21897,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-03T16:18:25.120Z","addedAt":"2026-09-03T17:50:35.633Z","updatedAt":"2026-09-22T17:50:41.451Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84963","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84963","note":"authoritative record"}]},{"id":"576a07b7-8586-47e3-9078-db54a28c0c1a","slug":"cve-2026-84970","externalId":"CVE-2026-84970","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84970 — A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library.","description":"A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application hands to the library's public JSON parsing interface, when that text is very large, can cause the library to read memory beyond the supplied buffer and return it to the caller, to silently accept only part of the input as a complete document, or to terminate the process. No MongoDB server, credentials, or non-default configuration is required; the effect is confined to the process that uses the library.","cveId":"CVE-2026-84970","cvssScore":5.9,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"mongodb","product":"c++ driver","affectedVersions":[">= 3.2.0, < 4.5.2"],"cwes":["CWE-681"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://jira.mongodb.org/browse/CXX-3547","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00124,"epssPercentile":0.01875,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-03T15:17:36.403Z","addedAt":"2026-09-03T15:50:35.240Z","updatedAt":"2026-09-10T21:50:34.616Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84970","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84970","note":"authoritative record"}]},{"id":"41e55f6b-7dd9-4396-a107-027a65f4a8f4","slug":"cve-2026-82522","externalId":"CVE-2026-82522","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-82522 — libjxl before 0.12 contains an integer underflow vulnerability in the container box parser that allows remote attackers to inject arbitrary metadat…","description":"libjxl before 0.12 contains an integer underflow vulnerability in the container box parser that allows remote attackers to inject arbitrary metadata by exploiting 64-bit box size truncation to size_t on 32-bit platforms. Attackers can supply a crafted JPEG XL file causing the decoder to parse attacker-controlled codestream bytes as phantom box headers, enabling injection of arbitrary metadata (Exif, XMP, IPTC, JUMBF) and potential out-of-bounds reads.","cveId":"CVE-2026-82522","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-681"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/libjxl/libjxl/commit/22ad80af1454f0444ea34115e49ed40517147d68","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/libjxl/libjxl/pull/4885","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/libjxl/libjxl/releases/tag/v0.12.0","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/libjxl-container-box-parser-integer-underflow-via-32-bit-size-truncation","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00407,"epssPercentile":0.329,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-02T18:21:27.587Z","addedAt":"2026-09-02T19:50:35.523Z","updatedAt":"2026-09-23T17:50:38.411Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82522","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-82522","note":"authoritative record"}]},{"id":"4117211e-a010-4bc8-80da-bbcb6f706823","slug":"cve-2026-82457","externalId":"CVE-2026-82457","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-82457 — su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncatio…","description":"su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to root's identifier, causing su-exec to execute target programs with root privileges instead of intended unprivileged accounts.","cveId":"CVE-2026-82457","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-681"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gist.github.com/thesmartshadow/ed96e2a88643c34a247c9b7cf9e311be","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/ncopa/su-exec","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/ncopa/su-exec/blob/89c016e6e08749d583efdeda04b9f73e1218e253/su-exec.c","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/su-exec-through-0.3-privilege-escalation-via-numeric-user-id","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.0018,"epssPercentile":0.06967,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-29T14:16:38.910Z","addedAt":"2026-08-29T15:50:29.963Z","updatedAt":"2026-09-23T17:50:38.360Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82457","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-82457","note":"authoritative record"}]},{"id":"4c1d7dc0-4d82-47b1-ac04-9acc151ca506","slug":"cve-2026-61799","externalId":"CVE-2026-61799","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash","description":"## Summary\n\n`io.netty.incubator:netty-incubator-codec-bhttp` uses attacker-controlled Binary HTTP variable-length integers as `long` values but accumulates them into `int` offsets. Large valid varint lengths wrap the internal offset negative, leading to unchecked `ArrayIndexOutOfBoundsException` / `IndexOutOfBoundsException` from a tiny malformed BHTTP payload. A remote peer can trigger connection-level denial of service in applications that expose `BinaryHttpParser` / `BinaryHttpDecoder` to untrusted input.\n\n## Details\n\nIn `codec-bhttp/src/main/java/io/netty/incubator/codec/bhttp/BinaryHttpParser.java`, several parser paths store cumulative byte offsets in `int sumBytes` and then add attacker-controlled `long` lengths using compound assignment. In Java, `int += long` narrows the result back to `int`, so a length such as `2^31` wraps `sumBytes` negative.\n\nPrimary request-control-data path:\n\n- `readRequestHead(...)` declares `int sumBytes = 0` at `BinaryHttpParser.java:386`.\n- It reads `methodLength` as a `long` at `BinaryHttpParser.java:394`.\n- It performs `sumBytes += methodLength` at `BinaryHttpParser.java:395`, narrowing the result to `int`.\n- If `methodLength` is `2^31`, `sumBytes` wraps negative and bypasses `if (sumBytes >= in.readableBytes()) return null` at `BinaryHttpParser.java:396-398`.\n- The parser then computes `schemeLengthIdx = in.readerIndex() + sumBytes` and calls `in.getByte(schemeLengthIdx)` at `BinaryHttpParser.java:401-402`, producing a negative index exception.\n\nThe same pattern is present in header parsing:\n\n- `readFieldLine(...)` uses `int sumBytes` and adds `long nameLength` / `long valueLength` at `BinaryHttpParser.java:659-680`.\n- `valueLengthIdx = nameIdx + (int) nameLength` at `BinaryHttpParser.java:674` can also overflow.\n\n`getIndeterminateLength(...)` similarly uses `int sumBytes` and `long possibleTerminator` at `BinaryHttpParser.java:544-553`.\n\n## Proof of concept\n\nSafe local verification performed in this repository. After compiling `codec-bhttp`, the following minimal verifier uses a 15-byte payload:\n\n```java\nimport io.netty.buffer.ByteBuf;\nimport io.netty.buffer.Unpooled;\nimport io.netty.incubator.codec.bhttp.BinaryHttpParser;\n\npublic final class VerifyBhttpOverflow {\n  public static void main(String[] args) {\n    byte[] payload = new byte[] {\n      0x00, (byte)0xc0, 0x00, 0x00, 0x00, (byte)0x80, 0x00, 0x00, 0x00,\n      0x47, 0x45, 0x54, 0x58, 0x58, 0x58\n    };\n    ByteBuf input = Unpooled.wrappedBuffer(payload);\n    try {\n      new BinaryHttpParser(8192).parse(input, false);\n      System.out.println(\"returned\");\n    } catch (Throwable t) {\n      System.out.println(t.getClass().getName());\n      System.out.println(t.getMessage());\n    }\n  }\n}\n```\n\nPayload interpretation:\n\n- `00`: known-length request frame indicator.\n- `c000000080000000`: valid 8-byte varint encoding of `0x80000000` (`2^31`) as the method length.\n- `474554585858`: a few dummy bytes so the parser proceeds far enough to compute the next index.\n\nObserved result:\n\n```text\njava.lang.ArrayIndexOutOfBoundsException\nIndex -2147483639 out of bounds for length 15\n```\n\nThe parser should reject the malformed/incomplete message with a controlled decoder exception or return `null` awaiting more bytes; it should not allow integer wraparound to reach unchecked buffer indexing.\n\n## Impact\n\nA remote peer can trigger an unchecked exception in the Binary HTTP decoder using a tiny payload. In typical Netty pipelines this closes or fails the affected channel. Depending on application-level exception handling, repeated payloads can cause sustained denial of service for exposed BHTTP endpoints. No memory corruption or information disclosure was observed because the failure occurs in Java/Netty bounds checks.\n\n## Suggested remediation\n\n- Use `long` for all cumulative byte counts derived from protocol lengths.\n- Before converting any protocol length to `int`, verify it is non-negative, no larger than `Integer.MAX_VALUE`, and no larger than available readable bytes and configured limits.\n- Replace `sumBytes >= in.readableBytes()` checks with precise checked arithmetic that permits exact-boundary complete fields but rejects impossible lengths.\n- Throw a controlled `CorruptedFrameException` / `TooLongFrameException` for invalid or unsupported lengths.\n- Add regression tests for 8-byte varint lengths at and above `Integer.MAX_VALUE` in request control data, response control data, known and indeterminate field sections, and field lines.\n\n## References\n\n- `codec-bhttp/src/main/java/io/netty/incubator/codec/bhttp/BinaryHttpParser.java:386-402`\n- `codec-bhttp/src/main/java/io/netty/incubator/codec/bhttp/BinaryHttpParser.java:659-680`\n- `codec-bhttp/src/main/java/io/netty/incubator/codec/bhttp/BinaryHttpParser.java:544-553`\n- RFC 9292: Binary Representation of HTTP Messages\n- RFC 9000 variable-length integer encoding","cveId":"CVE-2026-61799","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":"Maven","product":"io.netty.incubator:netty-incubator-codec-bhttp","affectedVersions":["pkg:maven/io.netty.incubator/netty-incubator-codec-bhttp < 0.0.23.Final"],"cwes":["CWE-190","CWE-248","CWE-681"],"tags":["osv","osv:ghsa-pgrf-4654-3gq8","ecosystem:maven"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-pgrf-4654-3gq8","type":"advisory","title":"OSV GHSA-pgrf-4654-3gq8"},{"url":"https://github.com/netty/netty-incubator-codec-ohttp/security/advisories/GHSA-pgrf-4654-3gq8","type":"other","title":"OSV web"},{"url":"https://github.com/netty/netty-incubator-codec-ohttp","type":"vendor","title":"OSV package"},{"url":"https://github.com/netty/netty-incubator-codec-ohttp/releases/tag/netty-incubator-codec-parent-ohttp-0.0.23.Final","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-20T18:43:21.000Z","addedAt":"2026-08-20T19:54:55.457Z","updatedAt":"2026-08-21T19:54:55.821Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61799","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61799","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-PGRF-4654-3GQ8"}]},{"id":"3fa38f55-7814-4bbd-b704-98ae52f773fd","slug":"cve-2026-75145","externalId":"CVE-2026-75145","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-75145 — FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c).","description":"FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison against the remaining frame size. On targets where long is 32 bits, including 64-bit Windows, sufficiently large OBU size values are sign-flipped by the narrowing cast, producing a negative value that passes the payload size check. This allows an oversized OBU to bypass the safety bound on affected platforms, leading to out-of-bounds memory access when the oversized value is subsequently used as a copy length.","cveId":"CVE-2026-75145","cvssScore":5.8,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-681"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b4c199c5906ff53368926c2a5839881f41957e7f","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24090","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ffmpeg-integer-narrowing-conversion-oob-memory-access-in-av1-rtp-packetizer","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00158,"epssPercentile":0.04395,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-19T17:21:12.863Z","addedAt":"2026-08-19T17:50:34.596Z","updatedAt":"2026-08-31T21:50:32.440Z","epssUpdatedAt":"2026-10-07T12:00:27.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75145","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-75145","note":"authoritative record"}]},{"id":"4cd76858-1506-4c05-8caa-e30dce0d241a","slug":"cve-2026-19879","externalId":"CVE-2026-19879","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19879 — A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path.","description":"A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes when writing HTTP response header values. A remote attacker can exploit this by supplying specific Unicode characters in user-controlled input that an application places into response headers. This can lead to the truncation of these characters into ASCII control characters or special symbols, potentially resulting in limited integrity impact or information disclosure if the application does not properly sanitize user input.","cveId":"CVE-2026-19879","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-681"],"tags":["nvd","status:received","status:undergoing-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-19879","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2516038","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00393,"epssPercentile":0.31297,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-14T15:17:09.310Z","addedAt":"2026-08-14T15:50:26.764Z","updatedAt":"2026-08-14T19:50:28.145Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19879","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19879","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":31,"totalPages":2,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:47:30.691Z","durationMs":26,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-681"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}