{"success":true,"data":{"threats":[{"id":"d6bbe1a7-c8fe-4f7a-a8a2-6d7b4396c996","slug":"ghsa-rp9v-7xv3-r6g3","externalId":"GHSA-rp9v-7xv3-r6g3","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Coraza: Resource exhaustion via deferred file handle accumulation in multipart body processor","description":"## Summary\n\n`defer temp.Close()` sits inside a `for` loop in the multipart processor. Go defers run at function return, not loop end, so every file part in the request holds an open fd until `ProcessRequest()` exits. Send enough parts and you hit `EMFILE`. With CRS loaded, that flips `MULTIPART_STRICT_ERROR` to 1 and rule `200001` starts returning 400s, including on legitimate requests hitting the same condition.\n\n## Details\n\n`internal/bodyprocessors/multipart.go`, line 69:\n\n```go\nfor {\n    p, err := mr.NextPart()\n    // ...\n    temp, err := os.CreateTemp(storagePath, \"crzmp*\")\n    defer temp.Close() // wrong scope\n    io.Copy(temp, p)\n}\n```\n\nEach iteration opens a temp file and defers its close. All of them stack up and fire together when `ProcessRequest` returns. 500 parts, 500 fds held simultaneously.\n\nThe body size limit (default 128MB) caps total bytes, not part count. A minimal file part (boundary line, `Content-Disposition` with `filename=`, one byte of content) is about 104 bytes. That's roughly 65,000 parts per 6.8MB of body, which on a standard Linux system (hard fd limit 65536) is enough to exhaust the table.\n\nFix is straightforward: call `temp.Close()` explicitly after `io.Copy` instead of deferring it.\n\n## PoC\n\nTested on v3.7.0 (`db9850b`), Go 1.25, Linux x86_64.\n\nAdd this file at `internal/bodyprocessors/poc_fd_test.go` and run:\n\n```text\ngo test -v -run TestMultipartFDLeak ./internal/bodyprocessors/...\n```\n\n```go\npackage bodyprocessors_test\n\nimport (\n\t\"fmt\"\n\t\"os\"\n\t\"strings\"\n\t\"sync\"\n\t\"sync/atomic\"\n\t\"testing\"\n\n\t\"github.com/corazawaf/coraza/v3/experimental/plugins/plugintypes\"\n\t\"github.com/corazawaf/coraza/v3/internal/bodyprocessors\"\n\t\"github.com/corazawaf/coraza/v3/internal/corazawaf\"\n)\n\nfunc countFDs() int {\n\te, _ := os.ReadDir(\"/proc/self/fd\")\n\treturn len(e)\n}\n\nfunc TestMultipartFDLeak(t *testing.T) {\n\tboundary := \"testboundary\"\n\tvar sb strings.Builder\n\tfor i := 0; i < 500; i++ {\n\t\tfmt.Fprintf(&sb, \"--%s\\r\\n\", boundary)\n\t\tfmt.Fprintf(&sb, \"Content-Disposition: form-data; name=\\\"f%d\\\"; filename=\\\"f%d.txt\\\"\\r\\n\", i, i)\n\t\tsb.WriteString(\"\\r\\n\")\n\t\tsb.WriteString(\"X\\r\\n\")\n\t}\n\tfmt.Fprintf(&sb, \"--%s--\\r\\n\", boundary)\n\n\tmp, _ := bodyprocessors.GetBodyProcessor(\"multipart\")\n\tbaseline := countFDs()\n\n\tvar peak int64\n\tdone := make(chan struct{})\n\tvar wg sync.WaitGroup\n\twg.Add(1)\n\tgo func() {\n\t\tdefer wg.Done()\n\t\tfor {\n\t\t\tselect {\n\t\t\tcase <-done:\n\t\t\t\treturn\n\t\t\tdefault:\n\t\t\t\tn := int64(countFDs())\n\t\t\t\tfor {\n\t\t\t\t\tcur := atomic.LoadInt64(&peak)\n\t\t\t\t\tif n <= cur || atomic.CompareAndSwapInt64(&peak, cur, n) {\n\t\t\t\t\t\tbreak\n\t\t\t\t\t}\n\t\t\t\t}\n\t\t\t}\n\t\t}\n\t}()\n\n\tv := corazawaf.NewTransactionVariables()\n\tmp.ProcessRequest(strings.NewReader(sb.String()), v,\n\t\tplugintypes.BodyProcessorOptions{\n\t\t\tMime:        \"multipart/form-data; boundary=\" + boundary,\n\t\t\tStoragePath: t.TempDir(),\n\t\t})\n\tclose(done)\n\twg.Wait()\n\n\tt.Logf(\"baseline=%d  peak=%d  spike=+%d\",\n\t\tbaseline, atomic.LoadInt64(&peak),\n\t\tatomic.LoadInt64(&peak)-int64(baseline))\n}\n```\n\nOutput:\n\n```text\nbaseline=7  peak=506  spike=+499\n```\n\nThe spike is ~1 fd per part. After `ProcessRequest` returns the deferred closes fire and it drops back to baseline.\n\n## Impact\n\n- **No authentication required.** Any endpoint that accepts multipart uploads is affected.\n- **fd exhaustion at ~6.8MB body (~65k parts).** `os.CreateTemp` starts returning errors and `MULTIPART_STRICT_ERROR` is set to 1.\n- **CRS false positives / DoS.** With CRS loaded, rule `200001` then blocks the request with a 400 — and any other multipart request processed concurrently that runs into the same condition gets blocked too. At that point the WAF can't distinguish the attack from a legitimate upload.\n- **Process-wide impact.** While the fd table is full the process can't open sockets or files for anything else either.\n- **Scope.** Affects all v3.x releases; the `defer` has been present since the multipart processor was introduced.","cveId":null,"cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":"Go","product":"github.com/corazawaf/coraza/v3","affectedVersions":["pkg:golang/github.com/corazawaf/coraza/v3 >= 3.0.0, < 3.8.0"],"cwes":["CWE-400","CWE-772"],"tags":["osv","osv:ghsa-rp9v-7xv3-r6g3","ecosystem:go"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-rp9v-7xv3-r6g3","type":"advisory","title":"OSV GHSA-rp9v-7xv3-r6g3"},{"url":"https://github.com/corazawaf/coraza/security/advisories/GHSA-rp9v-7xv3-r6g3","type":"other","title":"OSV web"},{"url":"https://github.com/corazawaf/coraza/commit/1bc39036e99c88e7de60cf8e6bb55ee4c311223c","type":"other","title":"OSV web"},{"url":"https://github.com/corazawaf/coraza","type":"vendor","title":"OSV package"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.8.0","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:52:00.000Z","addedAt":"2026-10-08T18:42:41.912Z","updatedAt":"2026-10-08T18:42:41.912Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-rp9v-7xv3-r6g3"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-rp9v-7xv3-r6g3"}]},{"id":"bd56a357-220c-4ff4-90f8-d8f92ce6f819","slug":"cve-2026-107286","externalId":"CVE-2026-107286","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107286 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.","description":"Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until 2.53.0, streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency can retain shared concurrency slots because anyio.CapacityLimiter associates an acquired slot with the borrowing task while streaming cleanup can run in a different task. Early stream termination, cancellation, consumer exceptions, or complete stream_text() consumption with debounce_by=0.1 can therefore leave capacity occupied, eventually preventing later requests that share the long-lived limiter from proceeding and causing a denial of service. Agent-level max_concurrency and non-streaming model requests are not affected. This issue is fixed in version 2.53.0.","cveId":"CVE-2026-107286","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"PyPI","product":"pydantic-ai","affectedVersions":["pkg:pypi/pydantic-ai >= 2.10.0, < 2.53.0","pkg:pypi/pydantic-ai-slim >= 2.10.0, < 2.53.0"],"cwes":["CWE-772"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-6fqq-452j-qhrp","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/pydantic/pydantic-ai/commit/453f19feeb7ab1d789f9393b1723c6a73b3d77b2","type":"other","title":"OSV web"},{"url":"https://github.com/pydantic/pydantic-ai/pull/9478","type":"other","title":"OSV web"},{"url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.53.0","type":"other","title":"OSV web"},{"url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-6fqq-452j-qhrp","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-6fqq-452j-qhrp","type":"advisory","title":"OSV GHSA-6fqq-452j-qhrp"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107286","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/pydantic/pydantic-ai","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:40.753Z","addedAt":"2026-10-08T16:39:35.734Z","updatedAt":"2026-10-08T21:08:30.837Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107286","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107286","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-6FQQ-452J-QHRP"}]},{"id":"a2779ee7-b051-455a-b7b7-62e91da8ab5b","slug":"cve-2026-104045","externalId":"CVE-2026-104045","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104045 — A flaw was found in SSSD.","description":"A flaw was found in SSSD. A local user can trigger a Denial of Service (DoS) by exploiting a race condition in the autofs responder between asynchronous enumeration completion and map invalidation. By repeatedly sending concurrent map enumeration and invalidation requests, an attacker can cause memory to leak, leading to excessive memory consumption that can disrupt or crash the autofs service.","cveId":"CVE-2026-104045","cvssScore":4.7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-772"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-104045","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2478663","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00095,"epssPercentile":0.00627,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T21:17:04.163Z","addedAt":"2026-10-06T22:39:32.873Z","updatedAt":"2026-10-07T16:39:31.183Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104045","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104045","note":"authoritative record"}]},{"id":"ee1af272-99d9-464d-8baf-d31f1eccad7c","slug":"cve-2026-104035","externalId":"CVE-2026-104035","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104035 — A flaw was found in SSSD.","description":"A flaw was found in SSSD. An issue in the Kerberos Credential Manager (KCM) responder allows a local user to cause a Denial of Service (DoS) by maintaining a persistent connection and repeatedly storing and destroying credentials. Because the service fails to release cached objects from memory when credentials are removed, memory consumption grows continuously, ultimately exhausting available memory and rendering the service unresponsive.","cveId":"CVE-2026-104035","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-772"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-104035","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2479107","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00095,"epssPercentile":0.00629,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T01:16:34.420Z","addedAt":"2026-10-06T01:50:41.289Z","updatedAt":"2026-10-08T04:39:32.264Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104035","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104035","note":"authoritative record"}]},{"id":"ce04d923-3e4b-4ddb-8c43-eb7e7b63729b","slug":"cve-2026-104031","externalId":"CVE-2026-104031","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104031 — A flaw was found in SSSD.","description":"A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory allocated during successful request processing is not released until the client connection terminates. A local attacker can exploit this vulnerability by maintaining an open connection and repeatedly submitting valid requests, leading to memory exhaustion and a Denial of Service (DoS).","cveId":"CVE-2026-104031","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-772"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-104031","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2479418","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00095,"epssPercentile":0.00629,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T01:16:33.843Z","addedAt":"2026-10-06T01:50:41.264Z","updatedAt":"2026-10-06T15:50:58.981Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104031","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104031","note":"authoritative record"}]},{"id":"c15d9383-3530-4ab4-b0a3-d7f079962de2","slug":"cve-2026-94651","externalId":"CVE-2026-94651","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94651 — improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings.","description":"improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-94651","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-755","CWE-772"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/rflzpdvtk8yhpzg99wkf5yf277nn7267","type":"advisory","title":"security@apache.org"}],"epssScore":0.00467,"epssPercentile":0.38463,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T11:17:38.890Z","addedAt":"2026-10-02T11:50:39.921Z","updatedAt":"2026-10-08T00:39:29.162Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94651","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94651","note":"authoritative record"}]},{"id":"ff2d5491-b204-4400-94c5-1537aeb7806b","slug":"cve-2026-93926","externalId":"CVE-2026-93926","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93926 — Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTran…","description":"Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-93926","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-401","CWE-772"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/9353rb8mpoq4ltff88h1j2y3hfy6blgb","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.34837,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T11:17:37.960Z","addedAt":"2026-10-02T11:50:39.889Z","updatedAt":"2026-10-02T15:50:40.659Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93926","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93926","note":"authoritative record"}]},{"id":"0198fb14-2e75-48f4-9ee0-e38a95d01bc6","slug":"cve-2026-97686","externalId":"CVE-2026-97686","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97686 — Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel …","description":"Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09.","cveId":"CVE-2026-97686","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-772"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support2.windriver.com/index.php?page=cve&order_by=cve_modified_date&order_way=asc#list","type":"advisory","title":"0bf9931a-6ebf-4f48-bd14-39ee5e1d61f8"}],"epssScore":0.00098,"epssPercentile":0.00742,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T19:16:50.867Z","addedAt":"2026-09-28T19:50:39.877Z","updatedAt":"2026-09-28T23:50:39.263Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97686","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97686","note":"authoritative record"}]},{"id":"71e624d5-99bf-4219-988e-bffe252910f9","slug":"cve-2026-100657","externalId":"CVE-2026-100657","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100657 — Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder.","description":"Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder. Once a frame's declared content-length has been fully read, the decoder allocates a chunk buffer from the channel allocator and parks it in an instance field while waiting for the single NUL byte that terminates the frame. If that byte never arrives, the buffer is never released: the replay Signal thrown by skipNullCharacter extends Error rather than Exception, so the decoder's catch(Exception) release path does not run, and StompSubframeDecoder overrides neither handlerRemoved0 nor channelInactive, so the buffer also survives channel teardown. A remote peer can leak one allocator buffer per connection by sending a complete, well-formed frame body and withholding its terminating NUL byte; with the default pooled allocator the memory is never returned to the pool or reclaimed by garbage collection, so the leak accumulates for the lifetime of the process and can lead to memory exhaustion. This affects versions up to and including 4.1.137.Final and versions 4.2.0.Final through 4.2.17.Final; it is fixed in 4.1.138.Final and 4.2.18.Final.","cveId":"CVE-2026-100657","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-772"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/netty/netty/security/advisories/GHSA-ghg5-c4jg-8q5j","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/netty-before-4.1.138-final-bytebuf-leak-in-stompsubframedecoder","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00344,"epssPercentile":0.25331,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-26T14:16:48.540Z","addedAt":"2026-09-26T15:50:38.119Z","updatedAt":"2026-09-28T15:50:45.478Z","epssUpdatedAt":"2026-09-28T12:03:10.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100657","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100657","note":"authoritative record"}]},{"id":"23d3553a-ef8b-4c30-9859-c8757459452c","slug":"cve-2026-100079","externalId":"CVE-2026-100079","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100079 — In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: unregister debugfs entries on teardown\n\nucsi_register() crea…","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: unregister debugfs entries on teardown\n\nucsi_register() creates per-instance debugfs entries, but\nucsi_unregister() keeps them around until ucsi_destroy().\n\nDrivers like ucsi_glink that unregister/register the same UCSI\ninstance across remoteproc restart then try to create an already\nexisting debugfs directory and log:\n\n  debugfs: 'pmic_glink.ucsi.0' already exists in 'ucsi'\n\nUnregister debugfs entries as part of ucsi_unregister(), and\nclear ucsi->debugfs after freeing it so repeated unregister\npaths remain safe.","cveId":"CVE-2026-100079","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"linux","product":"linux kernel","affectedVersions":[">= 6.6, < 6.6.157",">= 6.7, < 6.12.110",">= 6.13, < 6.18.52",">= 6.19, < 7.2.6"],"cwes":["CWE-772"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://git.kernel.org/stable/c/1f44d001620fd3caa30619a9bc73e9d15555408b","https://git.kernel.org/stable/c/62efee351566321ad72a4abaf6eb7d972590585d","https://git.kernel.org/stable/c/7177c215e69658adbd2f2fc5b72e14be9208d2ba","https://git.kernel.org/stable/c/eed73a65ab609b79d53de88cccc34b36dfe753c4","https://git.kernel.org/stable/c/fb7393519908befdc094be4ea913f582adbf2f7c"],"references":[{"url":"https://git.kernel.org/stable/c/1f44d001620fd3caa30619a9bc73e9d15555408b","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/62efee351566321ad72a4abaf6eb7d972590585d","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/7177c215e69658adbd2f2fc5b72e14be9208d2ba","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/eed73a65ab609b79d53de88cccc34b36dfe753c4","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/fb7393519908befdc094be4ea913f582adbf2f7c","type":"patch","title":"Patch"}],"epssScore":0.00114,"epssPercentile":0.01354,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-25T14:17:15.000Z","addedAt":"2026-09-25T15:50:39.283Z","updatedAt":"2026-10-02T21:50:39.793Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100079","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100079","note":"authoritative record"}]},{"id":"e16f5ce4-9fab-42a0-ade6-cef5d5846df3","slug":"cve-2026-79677","externalId":"CVE-2026-79677","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-79677 — Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a…","description":"Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lost time outs for asynchronous WebSocket writes.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.\n\n\n\nThe following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected.\n\n\n\nUsers are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.","cveId":"CVE-2026-79677","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-772","CWE-1025"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/bzwps6ck4szf2hmksbbon3syyl9qnkv8","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/23/27","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00322,"epssPercentile":0.23267,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T12:17:07.593Z","addedAt":"2026-09-23T13:50:38.711Z","updatedAt":"2026-09-23T19:50:41.307Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79677","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-79677","note":"authoritative record"}]},{"id":"27a771cb-0de6-4eb4-86d8-6d944a60ee65","slug":"cve-2026-94625","externalId":"CVE-2026-94625","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94625 — vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer pla…","description":"vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, causing valid requests to be delayed by up to 480 seconds while health checks continue returning success.","cveId":"CVE-2026-94625","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"vllm","product":"vllm","affectedVersions":["<= 0.29.0","pkg:pypi/vllm < 0.30.0"],"cwes":["CWE-772"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed","osv","osv:pysec-2026-4007","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/vllm-project/vllm/pull/51236"],"references":[{"url":"https://github.com/vllm-project/vllm","type":"vendor","title":"OSV package"},{"url":"https://github.com/vllm-project/vllm/blob/v0.29.0/vllm/distributed/kv_transfer/kv_connector/v1/mooncake/mooncake_connector.py#L1234-L1242","type":"other","title":"OSV web"},{"url":"https://github.com/vllm-project/vllm/pull/51236","type":"patch","title":"OSV fix"},{"url":"https://www.vulncheck.com/advisories/vllm-through-0.29.0-resource-exhaustion-via-ownerless-mooncake-transfer-placeholders","type":"advisory","title":"OSV advisory"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4007","type":"advisory","title":"OSV PYSEC-2026-4007"}],"epssScore":0.00521,"epssPercentile":0.42431,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-21T22:17:01.433Z","addedAt":"2026-09-21T23:50:36.720Z","updatedAt":"2026-09-30T13:54:30.032Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94625","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94625","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/PYSEC-2026-4007"}]},{"id":"b7d0f4ae-0ec5-4061-bd1a-f5355a551aa6","slug":"cve-2026-92230","externalId":"CVE-2026-92230","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-92230 — Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads.","description":"Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader's pinned in memory and unreachable for garbage collection, leading to unbounded Metaspace growth and eventual denial of service of the Karaf instance.","cveId":"CVE-2026-92230","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-401","CWE-772"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/pxgqjvsmzgpvgly1qf1w300qxsp8bxdj","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/17/3","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00488,"epssPercentile":0.40043,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T19:17:06.897Z","addedAt":"2026-09-17T19:50:38.385Z","updatedAt":"2026-09-18T19:50:40.305Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92230","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-92230","note":"authoritative record"}]},{"id":"696f5e03-8641-4372-8885-56ff0f5bda63","slug":"cve-2026-85718","externalId":"CVE-2026-85718","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85718 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero leaks one connection permit whenever TLS connection establishment fails before the handshake completes. NettyConnectListener removes the partitionKeyLock permit from NettyResponseFuture before every failure path is bound to the channel closeFuture, so an abort can leave the permit unreleased. Repeated failures can permanently lock out one host under a per-host limit or drain the shared pool under a global limit, blocking later requests even when no connection remains open. The default unlimited connection setting is not affected. This issue is fixed in version 3.0.12.","cveId":"CVE-2026-85718","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-400","CWE-772"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/64eb57af52a003ae7f29a2f9f4502271bbb138dd","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/issues/2189","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/pull/2288","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-gcmv-gr82-6m8v","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00533,"epssPercentile":0.43219,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T16:18:16.113Z","addedAt":"2026-09-17T17:50:44.360Z","updatedAt":"2026-09-30T17:50:44.533Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85718","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85718","note":"authoritative record"}]},{"id":"d8e7ea65-db70-4509-995d-e1a48fdec617","slug":"cve-2026-92983","externalId":"CVE-2026-92983","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-92983 — InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-fa…","description":"InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys. Unauthenticated attackers can send completion requests to the proxy endpoint that accumulate unreleased scheduler metadata and memory until the prefill worker is out-of-memory killed.","cveId":"CVE-2026-92983","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-772"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/InternLM/lmdeploy","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/InternLM/lmdeploy/blob/v0.17.0/lmdeploy/pytorch/disagg/conn/engine_conn.py#L93-L99","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/InternLM/lmdeploy/issues/4967","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.vulncheck.com/advisories/internlm-lmdeploy-through-0.17.0-memory-exhaustion-via-session-id-mismatch","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00658,"epssPercentile":0.49938,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T15:17:01.540Z","addedAt":"2026-09-17T15:50:39.334Z","updatedAt":"2026-09-22T21:50:39.856Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92983","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-92983","note":"authoritative record"}]},{"id":"69389189-d8c2-4302-b68a-02e74b4f6213","slug":"cve-2026-20250","externalId":"CVE-2026-20250","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-20250 — A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewa…","description":"A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability by sending a crafted stream of DTLS traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.","cveId":"CVE-2026-20250","cvssScore":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-772"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dtls-dos-Kp57HkyO","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00549,"epssPercentile":0.44202,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T21:17:08.713Z","addedAt":"2026-09-16T21:50:39.041Z","updatedAt":"2026-09-18T13:50:50.548Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20250","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-20250","note":"authoritative record"}]},{"id":"26ce2a09-b2f7-41ad-a95a-d4f8472914b3","slug":"cve-2026-63128","externalId":"CVE-2026-63128","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-63128 — RMCP is an official Rust SDK for the Model Context Protocol.","description":"RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-formed JSON-RPC POST that is not an initialization request, or an initialization request with a mismatched protocol header, causing StreamableHttpService::handle_post to call LocalSessionManager.create_session before validating the message. An early validation failure returns without removing the inserted LocalSessionHandle from LocalSessionManager.sessions, permanently retaining session and channel state for the server process lifetime. Repeated requests can grow the shared session table without bound, degrade legitimate-client latency through lock contention, exhaust memory, and terminate the server. This issue is fixed in version 2.0.0.","cveId":"CVE-2026-63128","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"crates.io","product":"rmcp","affectedVersions":["pkg:cargo/rmcp < 2.0.0"],"cwes":["CWE-400","CWE-401","CWE-772"],"tags":["nvd","status:received","osv","osv:ghsa-9pj6-vhgr-3mwh","ecosystem:crates.io","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/modelcontextprotocol/rust-sdk/commit/dfa7fd6f9309deab60bea230b041be9a3fcda846","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/modelcontextprotocol/rust-sdk/pull/934","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/modelcontextprotocol/rust-sdk/releases/tag/rmcp-v2.0.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/modelcontextprotocol/rust-sdk/security/advisories/GHSA-9pj6-vhgr-3mwh","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-9pj6-vhgr-3mwh","type":"advisory","title":"OSV GHSA-9pj6-vhgr-3mwh"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63128","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/modelcontextprotocol/rust-sdk","type":"vendor","title":"OSV package"}],"epssScore":0.0063,"epssPercentile":0.48555,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T15:17:39.960Z","addedAt":"2026-09-16T15:50:43.605Z","updatedAt":"2026-09-30T19:50:41.781Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63128","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-63128","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-9PJ6-VHGR-3MWH"}]},{"id":"ab54d5f8-50bd-4a4f-b353-2d9484aa2145","slug":"cve-2026-72931","externalId":"CVE-2026-72931","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-72931 — Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny servi…","description":"Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.","cveId":"CVE-2026-72931","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"microsoft","product":"windows 10 1607","affectedVersions":["< 10.0.14393.9512","< 10.0.17763.9245","< 10.0.19044.7725","< 10.0.19045.7725","< 10.0.22631.7582","< 10.0.26100.9445","< 10.0.26200.9445","< 10.0.28000.2954","r2","< 10.0.20348.5622","< 10.0.26100.33438"],"cwes":["CWE-772"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72931"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72931","type":"patch","title":"Patch"}],"epssScore":0.00344,"epssPercentile":0.2582,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T18:20:17.613Z","addedAt":"2026-09-08T19:50:41.835Z","updatedAt":"2026-09-24T23:50:41.154Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72931","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-72931","note":"authoritative record"}]},{"id":"7b2741cc-5b5a-419f-af33-4aa487ca75eb","slug":"cve-2026-18149","externalId":"CVE-2026-18149","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-18149 — undici's retry handler can leave an already-exposed response body pending forever.","description":"undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that declares a Content-Length, sends only part of the body, and closes the connection, the retry handler retries the request. If the retry returns a non-retryable status such as 400, the handler forwards that new response downstream and replaces its internal response stream, but the original response body that the application still holds is never ended or destroyed. As a result calls that read that body never settle, and the configured body timeout does not fire because its timer is tied to the connection parser rather than the orphaned body. An attacker-controlled server can trigger this with two short responses without keeping a connection open, and repeated requests accumulate pending promises and streams that can exhaust application concurrency or memory. This affects undici versions from 7.11.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.","cveId":"CVE-2026-18149","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"nodejs","product":"undici","affectedVersions":[">= 7.11.0, < 7.29.1",">= 8.0.0, < 8.10.2","pkg:npm/undici >= 7.11.0, < 7.29.1","pkg:npm/undici >= 8.0.0, < 8.10.2"],"cwes":["CWE-772"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed","osv","osv:ghsa-pmjh-fq2x-6v4x","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","type":"other","title":"OSV web"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-pmjh-fq2x-6v4x","type":"advisory","title":"OSV GHSA-pmjh-fq2x-6v4x"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18149","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/nodejs/undici/commit/3c6726599cea8646384dde846c97d630da472a74","type":"other","title":"OSV web"},{"url":"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974","type":"other","title":"OSV web"},{"url":"https://hackerone.com/reports/3892751","type":"other","title":"OSV web"},{"url":"https://github.com/nodejs/undici","type":"vendor","title":"OSV package"},{"url":"https://github.com/nodejs/undici/releases/tag/v7.29.1","type":"other","title":"OSV web"},{"url":"https://github.com/nodejs/undici/releases/tag/v8.10.2","type":"other","title":"OSV web"}],"epssScore":0.0036,"epssPercentile":0.277,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-04T18:17:49.733Z","addedAt":"2026-09-04T19:50:33.222Z","updatedAt":"2026-09-29T19:54:25.323Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18149","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-18149","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-PMJH-FQ2X-6V4X"}]},{"id":"f54ea6c3-fefa-4b33-9887-9f3ee956c616","slug":"cve-2026-71380","externalId":"CVE-2026-71380","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-71380 — Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause den…","description":"Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with a large Content-Length and then stalling before the body is complete.\n\nhttpd_request_handler:handle_info/2 cancels the request timeout as soon as a parse step succeeds, which includes the headers, and the clause that handles a decoder asking for more data re-arms the socket with {active, once} without setting any further timer. httpd_request:whole_body/2 returns such a continuation whenever the bytes received are fewer than the announced Content-Length, so a well-formed request that stops mid-body leaves the worker waiting indefinitely. The periodic byte-rate check that would reclaim it is armed only when minimum_bytes_per_second is configured, which it is not by default. Repeating this across connections occupies every worker permitted by max_clients and denies service to legitimate clients at negligible bandwidth cost.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.","cveId":"CVE-2026-71380","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-772"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cna.erlef.org/cves/CVE-2026-71380.html","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/erlang/otp/commit/81b453aac5a006bb8d26405f2bc3cf24e9d7733c","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/erlang/otp/security/advisories/GHSA-5vp4-58hc-h8cc","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-71380","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://www.erlang.org/doc/system/versions.html#order-of-versions","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"}],"epssScore":0.00673,"epssPercentile":0.5061,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-01T15:17:24.637Z","addedAt":"2026-09-01T15:50:35.114Z","updatedAt":"2026-09-08T01:50:33.009Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71380","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-71380","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":53,"totalPages":3,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T00:25:29.963Z","durationMs":24,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-772"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}