{"success":true,"data":{"threats":[{"id":"9331aab3-7fa3-4e2b-9504-29ef19f94b78","slug":"cve-2026-107279","externalId":"CVE-2026-107279","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107279 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In 3.0.12, a peer offering only Digest qop=auth-int causes mutual-authentication verification to be skipped. AuthenticatorUtils.computeExpectedRspAuth returns no expected value for auth-int, and Interceptors treats that result as unverifiable but nonfatal, so a response with an invalid rspauth value is accepted. A peer that does not know the shared secret can therefore be accepted as the authenticated server. This issue is fixed in version 3.0.13.","cveId":"CVE-2026-107279","cvssScore":8.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-303","CWE-757"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/a5422493b638226666a1ecb5f82826c7c7845b99","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-qhv6-3pmh-95q4","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00358,"epssPercentile":0.27498,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:03.657Z","addedAt":"2026-10-07T22:39:36.793Z","updatedAt":"2026-10-08T21:05:45.054Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107279","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107279","note":"authoritative record"}]},{"id":"fb027b1d-b52d-48a8-b768-368532a235a4","slug":"cve-2026-107231","externalId":"CVE-2026-107231","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107231 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, Realm.Builder treats a Digest challenge that yields no usable nonce as a Basic challenge. A malicious origin or proxy can label a challenge Digest while omitting or emptying the nonce, causing the client to resend the username and password using reversible Basic authentication. Both origin and proxy challenge parsers are affected. This issue is fixed in versions 3.0.13 and 2.16.1.","cveId":"CVE-2026-107231","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0.Beta1, < 3.0.13","pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, < 2.16.1"],"cwes":["CWE-319","CWE-522","CWE-757"],"tags":["nvd","status:received","osv","osv:ghsa-rqf5-2wxv-rjf4","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/8376866aa9b5a7653ad19db9d472692f875caa83","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/c8d639bf6ac341d377d610a93570bcd15565f1a6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-rqf5-2wxv-rjf4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-rqf5-2wxv-rjf4","type":"advisory","title":"OSV GHSA-rqf5-2wxv-rjf4"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107231","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00237,"epssPercentile":0.13486,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:03.320Z","addedAt":"2026-10-07T22:39:36.777Z","updatedAt":"2026-10-08T21:05:45.000Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107231","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107231","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-RQF5-2WXV-RJF4"}]},{"id":"8e617b64-517f-4898-9bca-d9228dc1e8a5","slug":"cve-2026-102508","externalId":"CVE-2026-102508","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102508 — Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacke…","description":"Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client.\n\nThe defect manifests differently depending on the version:\n- In 0.9.0 through 0.11.0 a failed message-signature check is only logged and never enforced, and there is no mechanism to verify the server certificate: it is taken from the unauthenticated GetEndpoints discovery response and used to encrypt the user's password.\n- In 0.12.0 through 0.13.1 the signature check is inverted (valid signatures are rejected, invalid ones accepted), and server certificates are accepted without a trust anchor by default.\n- In all affected versions the default security policy is None. Starting with 0.12.0 the driver additionally continues silently at a weaker security policy than the one configured, and starting with 0.13.0 endpoint selection prefers the weakest matching endpoint.\n\nUsers checking only for one of these mechanisms may wrongly conclude they are unaffected.\n\nThis issue affects Apache PLC4X: from 0.9.0 before 1.0.0.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 verifies message signatures correctly, refuses to connect unless the server certificate can be verified against a configured trust store or pinned certificate, defaults to Basic256Sha256 with SignAndEncrypt, and fails the\nconnection if the negotiated security policy is weaker than the configured one.","cveId":"CVE-2026-102508","cvssScore":9.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295","CWE-347","CWE-757"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/o076mcnsx6wnqpdy780m7s6hddbbnjfw","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/30/4","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00134,"epssPercentile":0.02505,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T08:16:31.903Z","addedAt":"2026-09-30T09:50:38.777Z","updatedAt":"2026-09-30T17:50:46.996Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102508","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102508","note":"authoritative record"}]},{"id":"bfdc59c4-db5d-4a5d-961f-a1454f15ae22","slug":"cve-2026-89177","externalId":"CVE-2026-89177","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-89177 — WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability.","description":"WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.","cveId":"CVE-2026-89177","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-757"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.twcert.org.tw/en/cp-139-11200-ffc3c-2.html","type":"advisory","title":"twcert@cert.org.tw"},{"url":"https://www.twcert.org.tw/tw/cp-132-11201-658c0-1.html","type":"advisory","title":"twcert@cert.org.tw"}],"epssScore":0.00356,"epssPercentile":0.27229,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-11T08:16:48.813Z","addedAt":"2026-09-11T09:50:33.653Z","updatedAt":"2026-09-11T17:50:34.343Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89177","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-89177","note":"authoritative record"}]},{"id":"e84124a8-8d97-4f82-a666-e523ffe7a23b","slug":"cve-2026-59293","externalId":"CVE-2026-59293","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-59293 — Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption…","description":"Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM.\nSpring Integration 7.1.0\nSpring Integration 7.0.0 - 7.0.5\nSpring Integration 6.5.0 - 6.5.10\nSpring Integration 6.4.0 - 6.4.12","cveId":"CVE-2026-59293","cvssScore":6.6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","severity":"medium","vendor":"vmware","product":"spring integration","affectedVersions":[">= 6.4.0, < 6.4.13",">= 6.5.0, < 6.5.11",">= 7.0.0, < 7.0.5.1",">= 7.1.0, < 7.1.0.1"],"cwes":["CWE-757"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://spring.io/security/cve-2026-59293","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00239,"epssPercentile":0.13762,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-27T20:17:55.460Z","addedAt":"2026-08-27T21:50:34.194Z","updatedAt":"2026-08-31T23:50:30.543Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59293","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-59293","note":"authoritative record"}]},{"id":"30717933-df76-426a-81ba-183b0ee3d8aa","slug":"cve-2026-72889","externalId":"CVE-2026-72889","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-72889 — Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify.","description":"Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify.\n\nverify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to check a signature is chosen by whoever sent it, and nothing lets the verifying party pin the method instead. When a message names HMAC-SHA1 or HMAC-SHA256, the key is derived from consumer_secret and token_secret rather than from the key the provider deployed.\n\nA provider deployed on RSA-SHA1 holds only the consumer public key, and RFC 5849 does not use consumer_secret for that method, so the required parameter is filled with a placeholder. A client that names HMAC-SHA1 instead has its signature checked against that placeholder, so a guessable one is enough to forge requests for any consumer key and token.","cveId":"CVE-2026-72889","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-347","CWE-757"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://datatracker.ietf.org/doc/html/rfc5849#section-3.4.2","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://datatracker.ietf.org/doc/html/rfc5849#section-3.4.3","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://github.com/vurtdev/Net-OAuth/commit/c467adf45c8d77ac4b92ad78b3eebf949252ba7f.patch","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-c8rm-g5cm-4pf5","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/RRWO/Net-OAuth-0.33/changes","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/19/2","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00448,"epssPercentile":0.3697,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-19T08:17:13.833Z","addedAt":"2026-08-19T09:50:27.362Z","updatedAt":"2026-08-26T19:50:30.334Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72889","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-72889","note":"authoritative record"}]},{"id":"11c9ede0-e5ee-4026-8bfa-492b9c214c76","slug":"cve-2026-72887","externalId":"CVE-2026-72887","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-72887 — Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token.","description":"Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token.\n\nPassing a callback to the constructor selects OAuth 1.0a. get_request_token then revokes that choice when the request token response omits oauth_callback_confirmed, with no exception, no warning and no option to require 1.0a. The access token request is built from the OAuth 1.0 message class, which has no verifier parameter, so oauth_verifier is dropped from the request even when get_access_token was passed one.\n\noauth_verifier is the binding that OAuth 1.0a added between the authorization step and the token exchange. An application that asked for 1.0a and gets 1.0 is open to OAuth 1.0 session fixation, where an attacker obtains a request token, has the victim authorize it, and then completes the exchange themselves, linking the victim's provider account to a session the attacker controls. No attacker action sets up the downgrade: a provider that does not confirm the callback is enough.","cveId":"CVE-2026-72887","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-757"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://datatracker.ietf.org/doc/html/rfc5849#section-2.1","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://datatracker.ietf.org/doc/html/rfc5849#section-2.3","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://github.com/vurtdev/Net-OAuth/commit/fd505dac1988723ed96721657663f2e4ac731644.patch","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-jh72-4qq2-8j6g","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/RRWO/Net-OAuth-0.32/changes","type":"advisory","title":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/16/3","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00721,"epssPercentile":0.52518,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-16T14:16:54.860Z","addedAt":"2026-08-16T15:50:26.005Z","updatedAt":"2026-08-26T17:50:39.862Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72887","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-72887","note":"authoritative record"}]},{"id":"ac3dd26e-7bc9-4694-a75e-95e6ff3d9667","slug":"cve-2026-18691","externalId":"CVE-2026-18691","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-18691 — An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mech…","description":"An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be transmitted in a less-protected form, potentially allowing that credential to be recovered. If recovered, the credential could be used to authenticate as the internal superuser to nodes in the deployment.","cveId":"CVE-2026-18691","cvssScore":9,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"mongodb","product":"mongodb","affectedVersions":[">= 7.0.0, < 7.0.40",">= 8.0.0, < 8.0.29",">= 8.2.0, <= 8.2.12",">= 8.3.0, < 8.3.8","9.0.0","9.1.0"],"cwes":["CWE-757"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://jira.mongodb.org/browse/SERVER-130264","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00355,"epssPercentile":0.27203,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-11T19:17:22.903Z","addedAt":"2026-08-11T19:50:34.491Z","updatedAt":"2026-09-16T15:50:39.482Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18691","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-18691","note":"authoritative record"}]},{"id":"2e5d18b0-f379-4947-bb47-eb7563f08440","slug":"cve-2026-67336","externalId":"CVE-2026-67336","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-67336 — better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm an…","description":"better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of the required S256 method.","cveId":"CVE-2026-67336","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"npm","product":"better-auth","affectedVersions":["pkg:npm/better-auth < 1.6.11"],"cwes":["CWE-327","CWE-1188","CWE-757"],"tags":["nvd","status:received","osv","osv:ghsa-9h47-pqcx-hjr4","ecosystem:npm","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/better-auth/better-auth/security/advisories/GHSA-9h47-pqcx-hjr4","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/better-auth-before-insecure-cryptographic-defaults-via-oidcprovider","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://osv.dev/vulnerability/GHSA-9h47-pqcx-hjr4","type":"advisory","title":"OSV GHSA-9h47-pqcx-hjr4"},{"url":"https://github.com/better-auth/better-auth","type":"vendor","title":"OSV package"},{"url":"https://github.com/better-auth/better-auth/releases/tag/v1.6.11","type":"other","title":"OSV web"}],"epssScore":0.00236,"epssPercentile":0.13418,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-01T13:17:04.557Z","addedAt":"2026-08-01T13:33:43.469Z","updatedAt":"2026-09-08T21:50:34.499Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67336","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-67336","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-9H47-PQCX-HJR4"}]},{"id":"d958a5d8-308c-472b-978f-aad1c55fde6d","slug":"cve-2026-55953","externalId":"CVE-2026-55953","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-55953 — The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the …","description":"The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5 handler validates the negotiated protocol version and the downgrade sentinel but hands the server-chosen suite directly to ssl_handshake:handle_server_hello_extensions/9, which installs it without a membership check. The TLS 1.3 client path performs this check (per RFC 8446), so it is not affected.\n\nAn on-path attacker between the client and the intended server can respond with a ServerHello selecting an anonymous key exchange suite such as TLS_DH_anon_* or TLS_ECDH_anon_* that the client never offered. Anonymous suites do not require the server to present a certificate, so the entire verify_peer and cacerts configuration is bypassed: the attacker completes the handshake with its own ephemeral parameters, no certificate is validated, no hostname is checked, and ssl:connect returns {ok, Socket}. All subsequent application traffic is readable and modifiable by the attacker.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.15, from OTP 28.0 before OTP 28.5.0.4, and from OTP 29.0 before OTP 29.0.4, corresponding to ssl from 5.3.4 before 11.2.12.11, from 11.3 before 11.6.0.4, and from 11.7 before 11.7.4. Whether OTP before OTP 17.0, corresponding to ssl before 5.3.4, is affected is unknown.","cveId":"CVE-2026-55953","cvssScore":9.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":"erlang","product":"erlang/otp","affectedVersions":[">= 17.0, < 27.3.4.15",">= 28.0, < 28.5.0.4",">= 29.0, < 29.0.4",">= 5.3.4, < 11.2.12.11",">= 11.3, < 11.6.0.4",">= 11.7, < 11.7.4"],"cwes":["CWE-757"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","status:modified"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://cna.erlef.org/cves/CVE-2026-55953.html","https://github.com/erlang/otp/commit/064e236414614f9085cbbbd6eacf0e43c02d1b4b","https://github.com/erlang/otp/commit/0a82596d425abe43dc2e0b3d74aa1557ef74051c","https://github.com/erlang/otp/commit/e6ff938116b2872bccc478af7fefb56627285b77","https://osv.dev/vulnerability/EEF-CVE-2026-55953"],"references":[{"url":"https://cna.erlef.org/cves/CVE-2026-55953.html","type":"patch","title":"Patch"},{"url":"https://github.com/erlang/otp/commit/064e236414614f9085cbbbd6eacf0e43c02d1b4b","type":"patch","title":"Patch"},{"url":"https://github.com/erlang/otp/commit/0a82596d425abe43dc2e0b3d74aa1557ef74051c","type":"patch","title":"Patch"},{"url":"https://github.com/erlang/otp/commit/e6ff938116b2872bccc478af7fefb56627285b77","type":"patch","title":"Patch"},{"url":"https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882","type":"vendor","title":"Vendor Advisory"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-55953","type":"patch","title":"Patch"},{"url":"https://www.erlang.org/doc/system/versions.html#order-of-versions","type":"advisory","title":"Release Notes"}],"epssScore":0.00234,"epssPercentile":0.13084,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-27T16:17:49.500Z","addedAt":"2026-07-28T20:12:38.606Z","updatedAt":"2026-09-08T01:50:32.895Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55953","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-55953","note":"authoritative record"}]},{"id":"6ff201e7-641f-488f-97de-a8b3243f61bb","slug":"cve-2026-4942","externalId":"CVE-2026-4942","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-4942 — IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) …","description":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled in the server configuration.","cveId":"CVE-2026-4942","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","severity":"high","vendor":"ibm","product":"i","affectedVersions":["7.3","7.4","7.5","7.6"],"cwes":["CWE-757"],"tags":["nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7278992","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.0043,"epssPercentile":0.35224,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-17T20:17:23.560Z","addedAt":"2026-08-12T19:50:25.592Z","updatedAt":"2026-08-12T19:50:25.592Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4942","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-4942","note":"authoritative record"}]},{"id":"6ed93fdf-bf90-4f5e-a157-da82d2b9b124","slug":"cve-2026-53712","externalId":"CVE-2026-53712","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-53712 — SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authe…","description":"SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Prior to 3.3, a flaw in com.ongres.scram:scram-client and com.ongres.scram:scram-common allows an attacker capable of a TLS man-in-the-middle attack to silently downgrade a connection from SCRAM-SHA-256-PLUS with channel binding to standard SCRAM-SHA-256 without channel binding when TlsServerEndpoint processes an X.509 certificate using a modern signature algorithm such as Ed25519; getChannelBindingData() can return an empty byte array after NoSuchAlgorithmException, and the ScramClient builder treats that as absent channel-binding data. This issue is fixed in version 3.3.","cveId":"CVE-2026-53712","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-636","CWE-757"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ongres/scram/releases/tag/3.3","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ongres/scram/security/advisories/GHSA-p9jg-fcr6-3mhf","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.0026,"epssPercentile":0.16246,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-17T19:17:16.880Z","addedAt":"2026-07-28T20:12:26.324Z","updatedAt":"2026-07-28T20:12:26.324Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53712","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-53712","note":"authoritative record"}]},{"id":"8bddf0b3-f4ad-4020-b0a3-988674cf5286","slug":"cve-2025-10693","externalId":"CVE-2025-10693","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2025-10693 — When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-secure device.","description":"When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-secure device. This vulnerability exists in Silicon Labs' Z-Wave PIR Sensor Reference design delivered as part of SiSDK v2025.6.0 and v2025.6.1.","cveId":"CVE-2025-10693","cvssScore":7.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-757"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://community.silabs.com/068Vm00000WN3J0","type":"advisory","title":"product-security@silabs.com"}],"epssScore":0.00322,"epssPercentile":0.23204,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2025-10-31T20:15:41.360Z","addedAt":"2026-10-07T22:39:30.554Z","updatedAt":"2026-10-07T22:39:30.554Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-10693","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2025-10693","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":13,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T03:16:22.059Z","durationMs":18,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-757"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}