DEV Community

CVE Reports profile picture

CVE Reports

CVEReports provides daily, automated deep-dives into the latest vulnerabilities, transforming emerging threats into comprehensive technical intelligence.

Joined Joined on  Personal website https://www.cvereports.com
CVE-2025-53521: CVE-2025-53521: Unauthenticated Remote Code Execution in F5 BIG-IP APM

CVE-2025-53521: CVE-2025-53521: Unauthenticated Remote Code Execution in F5 BIG-IP APM

Comments
2 min read
GHSA-C279-989M-238F: GHSA-C279-989M-238F: Nil Pointer Dereference in Sliver C2 Reverse Tunnel Handler

GHSA-C279-989M-238F: GHSA-C279-989M-238F: Nil Pointer Dereference in Sliver C2 Reverse Tunnel Handler

Comments
2 min read
GHSA-46WH-3698-F2CX: CVE-2026-33186: Deny Rule Bypass in Traefik via gRPC-Go Path Canonicalization Flaw

GHSA-46WH-3698-F2CX: CVE-2026-33186: Deny Rule Bypass in Traefik via gRPC-Go Path Canonicalization Flaw

Comments
2 min read
GHSA-WPRJ-9CVC-5W37: GHSA-wprj-9cvc-5w37: Unauthenticated Access to Sensitive Data via Missing Authorization in AVideo

GHSA-WPRJ-9CVC-5W37: GHSA-wprj-9cvc-5w37: Unauthenticated Access to Sensitive Data via Missing Authorization in AVideo

Comments
2 min read
CVE-2026-34245: CVE-2026-34245: Missing Authorization and IDOR in WWBN AVideo PlayLists Plugin

CVE-2026-34245: CVE-2026-34245: Missing Authorization and IDOR in WWBN AVideo PlayLists Plugin

Comments
2 min read
CVE-2026-34247: CVE-2026-34247: Insecure Direct Object Reference and Information Disclosure in WWBN AVideo

CVE-2026-34247: CVE-2026-34247: Insecure Direct Object Reference and Information Disclosure in WWBN AVideo

Comments
2 min read
GHSA-5JVJ-HXMH-6H6J: GHSA-5JVJ-HXMH-6H6J: Authorization Bypass in OpenClaw Gateway HTTP Session History

GHSA-5JVJ-HXMH-6H6J: GHSA-5JVJ-HXMH-6H6J: Authorization Bypass in OpenClaw Gateway HTTP Session History

Comments
2 min read
GHSA-Q2QC-744P-66R2: GHSA-Q2QC-744P-66R2: OpenClaw session_status Sandbox Bypass via sessionId Resolution

GHSA-Q2QC-744P-66R2: GHSA-Q2QC-744P-66R2: OpenClaw session_status Sandbox Bypass via sessionId Resolution

Comments
2 min read
GHSA-52Q4-3XJC-6778: GHSA-52Q4-3XJC-6778: Authorization Bypass via Mutable Metadata in OpenClaw Google Chat Integration

GHSA-52Q4-3XJC-6778: GHSA-52Q4-3XJC-6778: Authorization Bypass via Mutable Metadata in OpenClaw Google Chat Integration

Comments
2 min read
GHSA-RHFG-J8JQ-7V2H: GHSA-rhfg-j8jq-7v2h: Server-Side Request Forgery via Unguarded Base URLs in OpenClaw Extensions

GHSA-RHFG-J8JQ-7V2H: GHSA-rhfg-j8jq-7v2h: Server-Side Request Forgery via Unguarded Base URLs in OpenClaw Extensions

Comments
2 min read
GHSA-3H52-CX59-C456: GHSA-3H52-CX59-C456: Denial of Service via Pre-Authentication JSON Parsing in OpenClaw Feishu Extension

GHSA-3H52-CX59-C456: GHSA-3H52-CX59-C456: Denial of Service via Pre-Authentication JSON Parsing in OpenClaw Feishu Extension

Comments
2 min read
GHSA-77W2-CRQV-CMV3: GHSA-77W2-CRQV-CMV3: Authorization Bypass via Legacy Card Callbacks in OpenClaw Feishu Integration

GHSA-77W2-CRQV-CMV3: GHSA-77W2-CRQV-CMV3: Authorization Bypass via Legacy Card Callbacks in OpenClaw Feishu Integration

Comments
2 min read
GHSA-H4JX-HJR3-FHGC: GHSA-H4JX-HJR3-FHGC: Privilege Escalation via Synthetic Administrator Scopes in OpenClaw Gateway Plugin Subagent

GHSA-H4JX-HJR3-FHGC: GHSA-H4JX-HJR3-FHGC: Privilege Escalation via Synthetic Administrator Scopes in OpenClaw Gateway Plugin Subagent

Comments
2 min read
GHSA-RF6H-5GPW-QRGQ: GHSA-RF6H-5GPW-QRGQ: Authorization Bypass in OpenClaw Microsoft Teams Extension via Invoke Activities

GHSA-RF6H-5GPW-QRGQ: GHSA-RF6H-5GPW-QRGQ: Authorization Bypass in OpenClaw Microsoft Teams Extension via Invoke Activities

Comments
2 min read
GHSA-MF5G-6R6F-GHHM: GHSA-MF5G-6R6F-GHHM: Pre-Authentication Rate-Limit Bypass in OpenClaw Synology Chat Plugin

GHSA-MF5G-6R6F-GHHM: GHSA-MF5G-6R6F-GHHM: Pre-Authentication Rate-Limit Bypass in OpenClaw Synology Chat Plugin

Comments
2 min read
GHSA-J4C9-W69R-CW33: GHSA-j4c9-w69r-cw33: Authorization Bypass in OpenClaw Telegram Integration via Inline Button Callbacks

GHSA-J4C9-W69R-CW33: GHSA-j4c9-w69r-cw33: Authorization Bypass in OpenClaw Telegram Integration via Inline Button Callbacks

Comments
2 min read
GHSA-4HMJ-39M8-JWC7: GHSA-4HMJ-39M8-JWC7: ANSI Escape Sequence Injection in OpenClaw ACP Prompts

GHSA-4HMJ-39M8-JWC7: GHSA-4HMJ-39M8-JWC7: ANSI Escape Sequence Injection in OpenClaw ACP Prompts

Comments
2 min read
GHSA-7FQQ-Q52P-2JJG: GHSA-7FQQ-Q52P-2JJG: Out-of-Bounds Read in OpenCC via Truncated UTF-8 Sequences

GHSA-7FQQ-Q52P-2JJG: GHSA-7FQQ-Q52P-2JJG: Out-of-Bounds Read in OpenCC via Truncated UTF-8 Sequences

Comments
2 min read
CVE-2026-33044: CVE-2026-33044: Stored Cross-Site Scripting in Home Assistant Map-Card

CVE-2026-33044: CVE-2026-33044: Stored Cross-Site Scripting in Home Assistant Map-Card

Comments
2 min read
CVE-2026-33045: CVE-2026-33045: Stored Cross-Site Scripting in Home Assistant History-Graph Card

CVE-2026-33045: CVE-2026-33045: Stored Cross-Site Scripting in Home Assistant History-Graph Card

Comments
2 min read
CVE-2026-33433: CVE-2026-33433: Authentication Spoofing via Header Canonicalization Bypass in Traefik Middlewares

CVE-2026-33433: CVE-2026-33433: Authentication Spoofing via Header Canonicalization Bypass in Traefik Middlewares

Comments
2 min read
GHSA-H8R8-WCCR-V5F2: GHSA-H8R8-WCCR-V5F2: Mutation-XSS via Re-Contextualization in DOMPurify

GHSA-H8R8-WCCR-V5F2: GHSA-H8R8-WCCR-V5F2: Mutation-XSS via Re-Contextualization in DOMPurify

Comments
2 min read
CVE-2026-29905: CVE-2026-29905: Persistent Denial of Service via Malformed Image Upload in Kirby CMS

CVE-2026-29905: CVE-2026-29905: Persistent Denial of Service via Malformed Image Upload in Kirby CMS

Comments
2 min read
GHSA-MVM6-F9R3-FGFX: GHSA-mvm6-f9r3-fgfx: JSON Policy Injection in AWS SDK for .NET CloudFront Signers

GHSA-MVM6-F9R3-FGFX: GHSA-mvm6-f9r3-fgfx: JSON Policy Injection in AWS SDK for .NET CloudFront Signers

Comments
2 min read
CVE-2026-4926: CVE-2026-4926: Regular Expression Denial of Service in pillarjs path-to-regexp

CVE-2026-4926: CVE-2026-4926: Regular Expression Denial of Service in pillarjs path-to-regexp

Comments
2 min read
CVE-2026-4923: CVE-2026-4923: Regular Expression Denial of Service (ReDoS) in path-to-regexp

CVE-2026-4923: CVE-2026-4923: Regular Expression Denial of Service (ReDoS) in path-to-regexp

Comments
2 min read
GHSA-9P93-7J67-5PC2: GHSA-9P93-7J67-5PC2: Missing Authorization in OpenClaw Gateway Session Termination

GHSA-9P93-7J67-5PC2: GHSA-9P93-7J67-5PC2: Missing Authorization in OpenClaw Gateway Session Termination

Comments
2 min read
GHSA-9HJH-FR4F-GXC4: GHSA-9HJH-FR4F-GXC4: Privilege Escalation via WebSocket Reconnect in OpenClaw Gateway

GHSA-9HJH-FR4F-GXC4: GHSA-9HJH-FR4F-GXC4: Privilege Escalation via WebSocket Reconnect in OpenClaw Gateway

Comments
1 min read
GHSA-FQW4-MPH7-2VR8: GHSA-FQW4-MPH7-2VR8: OpenClaw Gateway Silent Privilege Escalation via Shared-Auth Reconnect

GHSA-FQW4-MPH7-2VR8: GHSA-FQW4-MPH7-2VR8: OpenClaw Gateway Silent Privilege Escalation via Shared-Auth Reconnect

Comments
2 min read
GHSA-XQ8G-HGH6-87HV: GHSA-xq8g-hgh6-87hv: Missing Rate Limiting in OpenClaw BlueBubbles Webhook Enables Brute-Force Attacks

GHSA-XQ8G-HGH6-87HV: GHSA-xq8g-hgh6-87hv: Missing Rate Limiting in OpenClaw BlueBubbles Webhook Enables Brute-Force Attacks

Comments
2 min read
GHSA-9WQX-G2CW-VC7R: GHSA-9WQX-G2CW-VC7R: Authorization Bypass in OpenClaw Matrix Verification Router

GHSA-9WQX-G2CW-VC7R: GHSA-9WQX-G2CW-VC7R: Authorization Bypass in OpenClaw Matrix Verification Router

Comments
2 min read
GHSA-MW7W-G3MG-XQM7: GHSA-MW7W-G3MG-XQM7: Authorization Bypass in OpenClaw BlueBubbles Extension via Unfiltered Reactions

GHSA-MW7W-G3MG-XQM7: GHSA-MW7W-G3MG-XQM7: Authorization Bypass in OpenClaw BlueBubbles Extension via Unfiltered Reactions

Comments
2 min read
GHSA-VCX4-4QXG-MFP4: GHSA-VCX4-4QXG-MFP4: Missing Rate Limiting in OpenClaw Telegram Webhook Authentication

GHSA-VCX4-4QXG-MFP4: GHSA-VCX4-4QXG-MFP4: Missing Rate Limiting in OpenClaw Telegram Webhook Authentication

Comments
2 min read
GHSA-QM2M-28PF-HGJW: GHSA-QM2M-28PF-HGJW: Privilege Escalation via Incorrect Scope Assignment in OpenClaw Gateway Plugin

GHSA-QM2M-28PF-HGJW: GHSA-QM2M-28PF-HGJW: Privilege Escalation via Incorrect Scope Assignment in OpenClaw Gateway Plugin

Comments
2 min read
GHSA-443W-3RQ3-5M5H: GHSA-443w-3rq3-5m5h: Policy Injection via Improper Input Escaping in AWS SDK for Java v2 CloudFront Utilities

GHSA-443W-3RQ3-5M5H: GHSA-443w-3rq3-5m5h: Policy Injection via Improper Input Escaping in AWS SDK for Java v2 CloudFront Utilities

Comments
2 min read
CVE-2026-32241: CVE-2026-32241: Command Injection in Flannel Experimental Extension Backend

CVE-2026-32241: CVE-2026-32241: Command Injection in Flannel Experimental Extension Backend

1
Comments
2 min read
CVE-2026-33942: CVE-2026-33942: Insecure Deserialization to RCE in Saloon PHP

CVE-2026-33942: CVE-2026-33942: Insecure Deserialization to RCE in Saloon PHP

Comments
2 min read
CVE-2026-26061: CVE-2026-26061: Unauthenticated Denial of Service via Unbounded Memory Allocation in Fleet

CVE-2026-26061: CVE-2026-26061: Unauthenticated Denial of Service via Unbounded Memory Allocation in Fleet

Comments
2 min read
CVE-2026-32695: CVE-2026-32695: Ingress Rule Injection and Host Restriction Bypass in Traefik

CVE-2026-32695: CVE-2026-32695: Ingress Rule Injection and Host Restriction Bypass in Traefik

Comments
2 min read
GHSA-89V5-38XR-9M4J: GHSA-89V5-38XR-9M4J: Multiple Server-Side Request Forgery (SSRF) Vectors in Postiz

GHSA-89V5-38XR-9M4J: GHSA-89V5-38XR-9M4J: Multiple Server-Side Request Forgery (SSRF) Vectors in Postiz

Comments
2 min read
CVE-2026-28786: CVE-2026-28786: Path Traversal and Information Disclosure in Open WebUI Audio Transcriptions

CVE-2026-28786: CVE-2026-28786: Path Traversal and Information Disclosure in Open WebUI Audio Transcriptions

Comments
2 min read
GHSA-CFP9-W5V9-3Q4H: GHSA-CFP9-W5V9-3Q4H: Filesystem Sandbox Bypass in OpenClaw Agent Media Tools

GHSA-CFP9-W5V9-3Q4H: GHSA-CFP9-W5V9-3Q4H: Filesystem Sandbox Bypass in OpenClaw Agent Media Tools

Comments
2 min read
GHSA-7XR2-Q9VF-X4R5: GHSA-7XR2-Q9VF-X4R5: Symlink Traversal via IDENTITY.md in OpenClaw

GHSA-7XR2-Q9VF-X4R5: GHSA-7XR2-Q9VF-X4R5: Symlink Traversal via IDENTITY.md in OpenClaw

Comments
2 min read
GHSA-HFF2-GCPX-8F4P: GHSA-HFF2-GCPX-8F4P: Apollo Router Core XS-Search Bypass via Read-Only CSRF

GHSA-HFF2-GCPX-8F4P: GHSA-HFF2-GCPX-8F4P: Apollo Router Core XS-Search Bypass via Read-Only CSRF

Comments
2 min read
GHSA-6P22-Q7W5-33PG: CVE-2026-25969: Local Denial of Service via Memory Leak in ImageMagick ASHLAR Coder

GHSA-6P22-Q7W5-33PG: CVE-2026-25969: Local Denial of Service via Memory Leak in ImageMagick ASHLAR Coder

Comments
2 min read
GHSA-9R56-3GJQ-HQF7: GHSA-9R56-3GJQ-HQF7: Memory Leak in ImageMagick META Reader Error Path

GHSA-9R56-3GJQ-HQF7: GHSA-9R56-3GJQ-HQF7: Memory Leak in ImageMagick META Reader Error Path

Comments
2 min read
GHSA-2J22-PR5W-6GQ8: GHSA-2j22-pr5w-6gq8: Cross-Site Scripting Filter Bypass in Loofah allowed_uri?

GHSA-2J22-PR5W-6GQ8: GHSA-2j22-pr5w-6gq8: Cross-Site Scripting Filter Bypass in Loofah allowed_uri?

Comments
2 min read
GHSA-PRH4-VHFH-24MJ: GHSA-PRH4-VHFH-24MJ: Information Exposure in Harbor Configuration Audit Logs

GHSA-PRH4-VHFH-24MJ: GHSA-PRH4-VHFH-24MJ: Information Exposure in Harbor Configuration Audit Logs

1
Comments
2 min read
GHSA-C7W3-X93F-QMM8: GHSA-C7W3-X93F-QMM8: SMTP Command Injection in Nodemailer via CRLF Sequences

GHSA-C7W3-X93F-QMM8: GHSA-C7W3-X93F-QMM8: SMTP Command Injection in Nodemailer via CRLF Sequences

Comments
2 min read
GHSA-WCJX-V2WJ-XG87: GHSA-WCJX-V2WJ-XG87: Denial of Service via Uncontrolled Recursion in pyasn1

GHSA-WCJX-V2WJ-XG87: GHSA-WCJX-V2WJ-XG87: Denial of Service via Uncontrolled Recursion in pyasn1

Comments
2 min read
GHSA-9Q82-XGWF-VJ6H: GHSA-9Q82-XGWF-VJ6H: XS-Search and CSRF Prevention Bypass in Apollo Server

GHSA-9Q82-XGWF-VJ6H: GHSA-9Q82-XGWF-VJ6H: XS-Search and CSRF Prevention Bypass in Apollo Server

Comments
2 min read
GHSA-PW7H-9G6P-C378: GHSA-pw7h-9g6p-c378: Authorization Bypass and Resource Exhaustion in OpenClaw Tlon Provider

GHSA-PW7H-9G6P-C378: GHSA-pw7h-9g6p-c378: Authorization Bypass and Resource Exhaustion in OpenClaw Tlon Provider

Comments
2 min read
GHSA-RM59-992W-X2MV: GHSA-RM59-992W-X2MV: Unauthenticated Resource Exhaustion and DoS in OpenClaw Voice Webhooks

GHSA-RM59-992W-X2MV: GHSA-RM59-992W-X2MV: Unauthenticated Resource Exhaustion and DoS in OpenClaw Voice Webhooks

Comments
2 min read
GHSA-48VW-M3QC-WR99: GHSA-48VW-M3QC-WR99: Improper Privilege Management in OpenClaw Gateway Trusted-Proxy Sessions

GHSA-48VW-M3QC-WR99: GHSA-48VW-M3QC-WR99: Improper Privilege Management in OpenClaw Gateway Trusted-Proxy Sessions

Comments
2 min read
GHSA-39PP-XP36-Q6MG: GHSA-39pp-xp36-q6mg: Remote Code Execution via Environment Variable Injection in OpenClaw

GHSA-39PP-XP36-Q6MG: GHSA-39pp-xp36-q6mg: Remote Code Execution via Environment Variable Injection in OpenClaw

Comments
2 min read
GHSA-WQ58-2PVG-5H4F: GHSA-WQ58-2PVG-5H4F: Improper Authorization and Privilege Escalation in OpenClaw Gateway Agent RPC

GHSA-WQ58-2PVG-5H4F: GHSA-WQ58-2PVG-5H4F: Improper Authorization and Privilege Escalation in OpenClaw Gateway Agent RPC

Comments
2 min read
GHSA-2PV8-4C52-MF8J: GHSA-2PV8-4C52-MF8J: Instance-Wide Data Breach via Auth Bypass and IDOR Chain in Vikunja

GHSA-2PV8-4C52-MF8J: GHSA-2PV8-4C52-MF8J: Instance-Wide Data Breach via Auth Bypass and IDOR Chain in Vikunja

Comments
2 min read
CVE-2026-32746: CVE-2026-32746: Pre-Authentication Remote Code Execution via BSS Overflow in GNU Inetutils telnetd

CVE-2026-32746: CVE-2026-32746: Pre-Authentication Remote Code Execution via BSS Overflow in GNU Inetutils telnetd

Comments
2 min read
CVE-2026-33675: CVE-2026-33675: Server-Side Request Forgery (SSRF) in Vikunja Task Migration

CVE-2026-33675: CVE-2026-33675: Server-Side Request Forgery (SSRF) in Vikunja Task Migration

Comments
2 min read
CVE-2026-33676: CVE-2026-33676: Cross-Project Information Disclosure in Vikunja API

CVE-2026-33676: CVE-2026-33676: Cross-Project Information Disclosure in Vikunja API

Comments
2 min read
loading...