{"success":true,"data":{"threats":[{"id":"18b70dcf-b1af-425f-8908-03e05668c463","slug":"cve-2026-107782","externalId":"CVE-2026-107782","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107782 — System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach pri…","description":"System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Microsoft-signed host like rundll32.exe, connect to SiSvcApiPort, and call PhSvcApiCreateService to execute code as SYSTEM.","cveId":"CVE-2026-107782","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/winsiderss/systeminformer","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/winsiderss/systeminformer/blob/v3.2.25011.2103/SystemInformer/phsvc/svcapiport.c#L196-L230","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/winsiderss/systeminformer/commit/ce451a264a424f6f386b1615df651f8364aaeb9f","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/winsiderss/systeminformer/releases/tag/v4.0.26241.138","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/system-informer-before-4.0.26241.138-incorrect-authorization-in-phsvc-alpc-port","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T21:17:53.227Z","addedAt":"2026-10-08T23:06:39.524Z","updatedAt":"2026-10-08T23:06:39.524Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107782","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107782","note":"authoritative record"}]},{"id":"a01a5b11-d109-4914-9845-206120efeaaf","slug":"cve-2026-107706","externalId":"CVE-2026-107706","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107706 — Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read per…","description":"Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.","cveId":"CVE-2026-107706","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Dolibarr/dolibarr","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Dolibarr/dolibarr/blob/24.0.1/htdocs/core/ajax/updateextrafield.php#L80","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Dolibarr/dolibarr/commit/3420d17b199059ac22fca8b59f23cb8962fc8ef8","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dolibarr-before-24.0.2-incorrect-authorization-via-updateextrafield-php","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:35.503Z","addedAt":"2026-10-08T21:05:53.311Z","updatedAt":"2026-10-08T23:06:39.341Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107706","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107706","note":"authoritative record"}]},{"id":"a484716a-6d6f-41e7-a7cd-3aaf564d9a6d","slug":"cve-2026-97147","externalId":"CVE-2026-97147","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97147 — In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object with a query that can return another project's res…","description":"In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object with a query that can return another project's resource, then write to it. An authenticated project member can use this to rewrite and un-publish another project's public action definitions and environments. A project administrator can create a workbook whose embedded ad-hoc action or workflow name collides with a resource of another project, which moves that resource into the caller's project and causes the original owner's subsequent updates of it to fail with server errors. Only deployments exposing the Mistral API are affected.","cveId":"CVE-2026-97147","cvssScore":7.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://launchpad.net/bugs/2160267","type":"advisory","title":"cve@mitre.org"},{"url":"https://security.openstack.org/ossa/OSSA-2026-044.html","type":"advisory","title":"cve@mitre.org"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:18:33.583Z","addedAt":"2026-10-08T18:39:31.998Z","updatedAt":"2026-10-08T23:06:39.069Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97147","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97147","note":"authoritative record"}]},{"id":"9e4e53b8-c984-457f-ad64-8baec69717aa","slug":"cve-2026-93861","externalId":"CVE-2026-93861","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93861 — In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow cre…","description":"In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow create a further membership naming a third project. The new membership row is created with its project_id defaulted to the accepting project rather than the original workflow owner, and thus the owner can neither see nor delete it. The third project can accept this membership (that it had not actually been granted by the owner), and then read and execute the owner's private workflow; only the accepting (not the owning) project can later revoke that access.","cveId":"CVE-2026-93861","cvssScore":6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://launchpad.net/bugs/2161277","type":"advisory","title":"cve@mitre.org"},{"url":"https://security.openstack.org/ossa/OSSA-2026-044.html","type":"advisory","title":"cve@mitre.org"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:18:31.153Z","addedAt":"2026-10-08T18:39:31.976Z","updatedAt":"2026-10-08T23:06:39.020Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93861","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93861","note":"authoritative record"}]},{"id":"f3aa2a85-c55b-4744-995e-c006de139176","slug":"cve-2026-107336","externalId":"CVE-2026-107336","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107336 — Malcolm's front nginx reverse proxy defines a \"Dashboards → Arkime shortcut\" location using a case-insensitive regex matcher but a case-sensitive r…","description":"Malcolm's front nginx reverse proxy defines a \"Dashboards → Arkime shortcut\" location using a case-insensitive regex matcher but a case-sensitive rewrite. A request whose path segment is not exact-lowercase (for example /IDDASH2ARK/...) enters the location (the matcher fires) but evades the rewrite (no redirect is issued), so nginx falls through to the location's proxy_pass to the Arkime backend. That location is the one proxied location in the shipped config that does not include the per-location authentication file, so the request reaches Arkime unauthenticated. The same location also forwards a client-supplied X-Forwarded-User header un-overwritten, and Arkime is configured to trust X-Forwarded-User as the authenticated username — so an unauthenticated network caller can reach the Arkime backend while supplying a forged, auto-provisioned identity.","cveId":"CVE-2026-107336","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290","CWE-441","CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://github.com/cisagov/Malcolm/security/advisories/GHSA-7j32-cf27-cp6h","type":"advisory","title":"ics-cert@hq.dhs.gov"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:20.177Z","addedAt":"2026-10-08T18:39:31.853Z","updatedAt":"2026-10-08T23:06:38.714Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107336","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107336","note":"authoritative record"}]},{"id":"d1d27d98-21a2-4ce1-806d-cedd7c2d3442","slug":"cve-2026-107334","externalId":"CVE-2026-107334","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107334 — Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g.","description":"Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx itself, however, selects which location block actually serves the request using the percent-decoded, normalized URI. Because the RBAC check never percent-decodes its input, an authenticated low-privilege user can request an admin-only path using percent-encoding (e.g. /%68tadmin.php) and have nginx route it to the restricted location while the Lua RBAC gate evaluating the un-decoded raw string finds no matching restriction and grants access.","cveId":"CVE-2026-107334","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://github.com/cisagov/Malcolm/security/advisories/GHSA-jr6p-63pg-hr6g","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:19.763Z","addedAt":"2026-10-08T18:39:31.839Z","updatedAt":"2026-10-08T23:06:38.678Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107334","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107334","note":"authoritative record"}]},{"id":"ccaeff77-f25f-4386-8307-89410155cf63","slug":"cve-2026-107333","externalId":"CVE-2026-107333","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107333 — Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authoriz…","description":"Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially formatted request path to bypass role-based restrictions and reach administrative or role gated endpoints they should not have access to. This affects all restricted paths protected by the RBAC authorization layer, including file upload, PHP server, htadmin, and authentication management interfaces.","cveId":"CVE-2026-107333","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://github.com/cisagov/Malcolm/security/advisories/GHSA-v66f-cwcm-hf73","type":"advisory","title":"ics-cert@hq.dhs.gov"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:19.603Z","addedAt":"2026-10-08T18:39:31.832Z","updatedAt":"2026-10-08T23:06:38.656Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107333","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107333","note":"authoritative record"}]},{"id":"75aa369e-3d10-4c37-84e7-ea29c05a7b8b","slug":"cve-2026-50055","externalId":"CVE-2026-50055","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-50055 — A policy-enforcement flaw in Zimbra Collaboration Suite allows an authenticated user to bypass disabled mail forwarding by using a Sieve notify act…","description":"A policy-enforcement flaw in Zimbra Collaboration Suite allows an authenticated user to bypass disabled mail forwarding by using a Sieve notify action to send copies of email content and headers to an arbitrary address.","cveId":"CVE-2026-50055","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories","type":"advisory","title":"cve@rapid7.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:17.307Z","addedAt":"2026-10-08T18:39:31.789Z","updatedAt":"2026-10-08T21:05:51.539Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50055","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-50055","note":"authoritative record"}]},{"id":"689658e2-2d74-44bc-92bc-587e43527623","slug":"cve-2026-60087","externalId":"GHSA-29r9-67vg-qj56","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: Human-in-the-loop tool approval is cached by tool name and silently reused for all subsequent calls with arbitrary arguments","description":"## Summary\n\nPraisonAI gates dangerous tools (file writes, deletes, shell/code execution) behind an interactive approval prompt. The first approval of a tool is cached for the remainder of the run and silently reused for all later invocations of that tool with arbitrary, unreviewed arguments.\n\n## Root cause\n\n`ApprovalRegistry.is_already_approved` (`src/praisonai-agents/praisonaiagents/approval/registry.py`, around line 181) returns `True` whenever the tool name is present in a per-run context set. The cache is keyed on tool name only — arguments are not part of the key.\n\n`approve_sync` / `approve_async` (around lines 224-226 / 278-279) short-circuit on that cache before the approval backend is consulted.\n\n`clear_approved` (around lines 186-187) is the only routine that clears the cache, but it is never invoked in the shipped library (only in tests). The cache persists for the entire agent run and is inherited by child tasks via `contextvars`.\n\nCritical-tier tools (`execute_command`, `execute_code`) are exempt from the cache. But high-risk tools like `write_file` are not.\n\n## Proof of concept\n\n```python\nfrom praisonaiagents.approval.registry import ApprovalRegistry\nfrom praisonaiagents.approval.protocols import ApprovalDecision, ApprovalRequest\n\nclass CountingBackend:\n    def __init__(self): self.prompts = []\n    def request_approval_sync(self, request):\n        self.prompts.append((request.tool_name, dict(request.arguments)))\n        return ApprovalDecision(approved=True, reason=\"human approved\")\n\nbackend = CountingBackend()\nreg = ApprovalRegistry()\nreg.set_backend(backend)\nreg.add_requirement(\"write_file\", \"high\")\n\nd1 = reg.approve_sync(\"agent\", \"write_file\", {\"path\": \"/tmp/safe.txt\", \"content\": \"hi\"})\n# Human prompted — approves a benign write\n\nd2 = reg.approve_sync(\"agent\", \"write_file\", {\"path\": \"/etc/crontab\", \"content\": \"* * * * * root evil\"})\n# NO prompt — auto-approved from cache\n\nassert len(backend.prompts) == 1\nassert d2.reason == \"Already approved in context\"\n```\n\nNegative control: `execute_command` (critical) re-prompts on every call — 2 prompts for 2 calls.\n\n## Impact\n\nA `write_file` approval for a benign path authorizes every later `write_file` call in the session with arbitrary arguments. A model steered by malicious input can write to sensitive locations with no further human prompt.\n\n## Suggested fix\n\n- Include arguments in the approval cache key, or re-prompt on argument change.\n- Expire the cache per-call or per-turn.\n- Do not inherit the cache into child tasks.","cveId":"CVE-2026-60087","cvssScore":null,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","severity":"medium","vendor":"PyPI","product":"praisonaiagents","affectedVersions":["pkg:pypi/praisonaiagents < 1.6.78"],"cwes":["CWE-863"],"tags":["osv","osv:ghsa-29r9-67vg-qj56","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-29r9-67vg-qj56","type":"advisory","title":"OSV GHSA-29r9-67vg-qj56"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-29r9-67vg-qj56","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60087","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62164","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-tool-approval-cache-bypass","type":"other","title":"OSV web"}],"epssScore":0.00148,"epssPercentile":0.03504,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:43:45.000Z","addedAt":"2026-10-08T18:42:42.460Z","updatedAt":"2026-10-08T18:42:42.460Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60087","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-60087","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-29r9-67vg-qj56"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-29r9-67vg-qj56"}]},{"id":"5410f918-5a94-4536-bf59-864f823f995c","slug":"cve-2026-14273","externalId":"CVE-2026-14273","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-14273 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a lo…","description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a local attacker to obtain sensitive information due to improper authorization.","cveId":"CVE-2026-14273","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7289775","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:48.733Z","addedAt":"2026-10-08T16:39:35.878Z","updatedAt":"2026-10-08T21:05:50.221Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14273","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-14273","note":"authoritative record"}]},{"id":"f3e675a2-9635-47af-8e27-92bac06a2388","slug":"cve-2026-105403","externalId":"CVE-2026-105403","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105403 — ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 allows a security policy bypass when a policy uses coder, rather than module, as its domain.","description":"ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 allows a security policy bypass when a policy uses coder, rather than module, as its domain. An attacker can supply a crafted image to evade coder-based policy restrictions, causing ImageMagick to process formats the administrator intended to block.","cveId":"CVE-2026-105403","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vcjj-32hg-qpx5","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-security-policy-bypass-via-coder-domain","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:33.637Z","addedAt":"2026-10-08T16:39:35.628Z","updatedAt":"2026-10-08T21:05:49.819Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105403","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105403","note":"authoritative record"}]},{"id":"085180b1-1a04-4a14-8165-48dbdecf60ca","slug":"cve-2026-71896","externalId":"CVE-2026-71896","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-71896 — An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolp…","description":"An authorization vulnerability in Apache DolphinScheduler allows authenticated users to retrieve other users' account information through the /dolphinscheduler/users/list-all endpoint without the required permissions.\n\n\n\nThe endpoint fails to enforce the necessary authorization checks before returning user account information. As a result, an authenticated user can access account information they are not authorized to view.\n\n\n\nSuccessful exploitation may expose sensitive user information and facilitate account enumeration.\n\n\n\nThis issue affects Apache DolphinScheduler: before 3.4.3.\n\n\n\nUsers are recommended to upgrade to version 3.4.3, which fixes the issue.","cveId":"CVE-2026-71896","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/f2c2rc1xhkxng3y1yo74yj21o11qydjb","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/08/6","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00164,"epssPercentile":0.05067,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T09:16:42.287Z","addedAt":"2026-10-08T10:39:34.965Z","updatedAt":"2026-10-08T18:39:31.174Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71896","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-71896","note":"authoritative record"}]},{"id":"deb84f56-0455-4180-a520-29e76d6b7984","slug":"cve-2026-71183","externalId":"CVE-2026-71183","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-71183 — An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authoriz…","description":"An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized to access through the /unauth-datasource and /authed-datasource endpoints.\n\n\n\nThese endpoints fail to enforce the required data source access controls and return sensitive connection information, including data source passwords. As a result, an authenticated user without permission to access a data source can retrieve its connection details and credentials.\n\n\n\nSuccessful exploitation exposes sensitive data source information and may enable unauthorized access to the underlying databases using the disclosed credentials.\n\n\n\nThis issue affects Apache DolphinScheduler: before 3.4.3.\n\n\n\nUsers are recommended to upgrade to version 3.4.3, which fixes the issue.","cveId":"CVE-2026-71183","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/9g0fx2kdqv9nj20k759shhly3vpg96mw","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/08/4","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.0015,"epssPercentile":0.03633,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T09:16:42.037Z","addedAt":"2026-10-08T10:39:34.951Z","updatedAt":"2026-10-08T18:39:31.159Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71183","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-71183","note":"authoritative record"}]},{"id":"f5602ac2-f9a8-429e-9e7e-5d7f9ecfcf36","slug":"cve-2026-66087","externalId":"CVE-2026-66087","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-66087 — An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not autho…","description":"An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the \n\n\n\n\n\n  *  /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop\n  *  /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/savepoint\n\n\n\n\n\n\n\n\nThis issue affects Apache DolphinScheduler: before 3.4.3.\n\n\n\nUsers are recommended to upgrade to version 3.4.3, which fixes the issue.","cveId":"CVE-2026-66087","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/pghhb42sbyv5dhx6clcj4hllxnh7c0dn","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/08/3","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00164,"epssPercentile":0.05076,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T09:16:41.910Z","addedAt":"2026-10-08T10:39:34.943Z","updatedAt":"2026-10-08T23:06:37.348Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66087","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-66087","note":"authoritative record"}]},{"id":"cc25ac3e-1db9-418a-9e8a-7e75aebaf29f","slug":"cve-2026-66084","externalId":"CVE-2026-66084","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-66084 — An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not aut…","description":"An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint.\n\n\n\nThe endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. An authenticated user can supply the code of a project they are authorized to access together with a task definition code from another project, bypassing project access restrictions and modifying the target task definition and its upstream dependencies.\n\n\n\nThis vulnerability can compromise workflow integrity and disrupt task execution in unauthorized projects.This issue affects Apache DolphinScheduler: before 3.4.3.\n\n\n\nUsers are recommended to upgrade to version 3.4.3, which fixes the issue.","cveId":"CVE-2026-66084","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/cn6v1m8pfnjn7rsqkq1xow8v63pw27w2","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/08/2","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00177,"epssPercentile":0.06618,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T09:16:41.783Z","addedAt":"2026-10-08T10:39:34.936Z","updatedAt":"2026-10-08T23:06:37.324Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66084","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-66084","note":"authoritative record"}]},{"id":"44edd8b5-b027-4327-a267-9c6f1721f83a","slug":"cve-2026-66082","externalId":"CVE-2026-66082","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-66082 — An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedule…","description":"An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedules, workflow definitions, and task instances in other projects.\n\n\n\nThe affected endpoints check permissions against the supplied projectCode but fail to verify that the target resource belongs to that project. An authenticated user with the required permissions in one project can supply that project's code together with a resource identifier from another project, bypassing the target project's access restrictions.\n\n\n\nThe affected endpoints include:\n\n  *  \n\nPOST /projects/{projectCode}/schedules/{id}/online and /offline: Activate or deactivate workflow schedules in another project.\n\n\n  *  \n\nPOST /projects/{projectCode}/workflow-definition/{code}/release: Change the ONLINE/OFFLINE state of workflow definitions in another project.\n\n\n\n\n\n\nSuccessful exploitation allows users to alter workflow availability and interfere with task execution in projects they are not authorized to access.\n\n\n\nThis issue affects Apache DolphinScheduler: before 3.4.3.\n\n\n\nUsers are recommended to upgrade to version 3.4.3, which fixes the issue.","cveId":"CVE-2026-66082","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread.html/lp124m92t6gfocqkm1h338674j2so9yc","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/08/1","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00188,"epssPercentile":0.07758,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T09:16:41.637Z","addedAt":"2026-10-08T10:39:34.928Z","updatedAt":"2026-10-08T23:06:37.297Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66082","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-66082","note":"authoritative record"}]},{"id":"5b54d27c-203e-481e-a677-d3d6e5f6c847","slug":"cve-2026-107450","externalId":"CVE-2026-107450","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107450 — In Stump through 0.1.10, the updateSmartList and deleteSmartList GraphQL mutations (crates/graphql/src/mutation/smart_lists.rs) depend only on the …","description":"In Stump through 0.1.10, the updateSmartList and deleteSmartList GraphQL mutations (crates/graphql/src/mutation/smart_lists.rs) depend only on the shared AccessSmartList permission and resolve the target list at Reader access (lacking a creator check). Any authenticated user with that permission can overwrite, delete, or take over another user's smart list. (updateSmartList sets creatorId to the caller identity, and can set visibility to PRIVATE, locking out the original owner.) NOTE: this is unrelated to the graphql crate on crates.io.","cveId":"CVE-2026-107450","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://crates.io/crates/graphql","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/kashishtopi/stump-smartlist-bola","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/stumpapp/stump/blob/42a9918/crates/graphql/src/mutation/smart_lists.rs","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00211,"epssPercentile":0.10493,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T05:17:04.477Z","addedAt":"2026-10-08T06:39:29.480Z","updatedAt":"2026-10-08T23:06:37.171Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107450","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107450","note":"authoritative record"}]},{"id":"2ea3aaf2-d8f9-4cc4-80ec-50a42d9f77fd","slug":"cve-2026-102488","externalId":"CVE-2026-102488","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102488 — In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain depl…","description":"In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them.","cveId":"CVE-2026-102488","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://advisories.octopus.com/post/2026/sa2026-12","type":"advisory","title":"security@octopus.com"}],"epssScore":0.00207,"epssPercentile":0.09899,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T02:16:53.003Z","addedAt":"2026-10-08T02:39:29.933Z","updatedAt":"2026-10-08T21:05:45.368Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102488","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102488","note":"authoritative record"}]},{"id":"1eb11baa-8f88-422e-88a6-86587d93c8c9","slug":"cve-2026-107281","externalId":"CVE-2026-107281","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107281 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excludes the authenticated principal for connection-oriented NTLM and Negotiate authentication. A pooled socket authenticated for one request can be reused by a request carrying another principal, and the server executes that later request as the first identity. Basic and Digest are not affected because they authenticate each request. This issue is fixed in versions 3.0.13 and 2.16.1.","cveId":"CVE-2026-107281","cvssScore":7.6,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-346","CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/73813babf51231ee79f7da4f07b777f19f48d34d","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/83e552e64cabab2119addb6b47f7c6482997c94e","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-2.16.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.13","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-vvp4-63h8-v5pm","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00171,"epssPercentile":0.05855,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:03.980Z","addedAt":"2026-10-07T22:39:36.808Z","updatedAt":"2026-10-08T21:05:45.106Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107281","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107281","note":"authoritative record"}]},{"id":"211b9c97-7fb8-4ffb-993b-ffd36a7cc765","slug":"cve-2026-107230","externalId":"CVE-2026-107230","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107230 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.","description":"The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT proxy logins can reuse a socket authenticated as a different identity. A later request is then executed under the first identity and can expose that identity's data or authority to another caller. In the affected execution path, SpnegoEngine, NTLM, Kerberos, SPNEGO, SOCKS, and CONNECT control or expose the vulnerable behavior. This issue is fixed in version 3.0.14.","cveId":"CVE-2026-107230","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":"Maven","product":"org.asynchttpclient:async-http-client","affectedVersions":["pkg:maven/org.asynchttpclient/async-http-client >= 3.0.0, < 3.0.14","pkg:maven/org.asynchttpclient/async-http-client >= 2.0.0, <= 2.16.1"],"cwes":["CWE-346","CWE-863"],"tags":["nvd","status:received","osv","osv:ghsa-v2j5-22fr-j62r","ecosystem:maven","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/AsyncHttpClient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.14","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v2j5-22fr-j62r","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-v2j5-22fr-j62r","type":"advisory","title":"OSV GHSA-v2j5-22fr-j62r"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107230","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/AsyncHttpClient/async-http-client","type":"vendor","title":"OSV package"}],"epssScore":0.00188,"epssPercentile":0.07716,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T22:17:03.133Z","addedAt":"2026-10-07T22:39:36.768Z","updatedAt":"2026-10-08T21:05:44.974Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107230","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107230","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-V2J5-22FR-J62R"}]}],"pagination":{"page":1,"limit":20,"total":1381,"totalPages":70,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:15:35.546Z","durationMs":53,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-863"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}