Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

Vulnerability disclosures

Vulnerabilities discovered by Cantina researchers and autonomous agents, coordinated with affected maintainers and published here after disclosure.

public disclosures
35
affected projects
19
Last disclosed

Filter & sort

Disclosures

35 of 35 disclosures

Public vulnerability disclosures, with product, finding, CVE, severity, and disclosure date
Product Finding CVE Severity Disclosed
CompCert x86-64 switch miscompilation can read beyond its jump table — CompCert, COMPCERT-595 No CVE identifier Unrated
Seagate openSeaChest SCSI defect count can overflow the defect-list allocation — Seagate openSeaChest, CVE-2026-10717 CVE-2026-10717 Low
Seagate openSeaChest NVMe deallocate loop can write a 257th descriptor — Seagate openSeaChest, CVE-2026-10718 CVE-2026-10718 Medium
Seagate openSeaChest FLBAS index can write beyond allocated format entries — Seagate openSeaChest, CVE-2026-10719 CVE-2026-10719 Low
CompCert Dropped tag binding can produce the wrong C struct layout — CompCert, COMPCERT-0375C18 No CVE identifier Medium
CompCert Win64 backend can corrupt nonvolatile XMM registers — CompCert, COMPCERT-584 No CVE identifier Medium
CompCert Newlines in filenames can inject ARM assembly — CompCert, COMPCERT-586 No CVE identifier High
Node.js Stale SQLite iterators can replay bound writes — Node.js, CVE-2026-58041 CVE-2026-58041 Medium
Node.js Large DNS responses can abort Node.js workers — Node.js, CVE-2026-58042 CVE-2026-58042 Medium
Adobe Content Credentials Improper input validation can permit limited unauthorized writes — Adobe Content Credentials, CVE-2026-71390 CVE-2026-71390 Medium
Ruby Prism UTF-8 stream reads can overflow Prism's fixed stack buffer — Ruby Prism, PRISM-4172 No CVE identifier High
RabbitMQ Direct-reply-to bindings enable cross-tenant injection — RabbitMQ, CVE-2026-57215 CVE-2026-57215 High
RabbitMQ Proxy handling bypasses loopback-only authentication — RabbitMQ, CVE-2026-57216 CVE-2026-57216 Medium
RabbitMQ Topic permissions fail open during metadata errors — RabbitMQ, CVE-2026-57217 CVE-2026-57217 High
RabbitMQ OAuth consumers retain access after token expiry — RabbitMQ, CVE-2026-57218 CVE-2026-57218 Medium
Node.js Unicode hostname separators bypass TLS wildcard depth — Node.js, CVE-2026-48618 CVE-2026-48618 High
Node.js Mixed-case SNI can bypass mTLS trust policies — Node.js, CVE-2026-48928 CVE-2026-48928 Medium
Node.js Embedded NUL bytes can silently rebind TLS authority — Node.js, CVE-2026-48930 CVE-2026-48930 Medium
Nextcloud Server Temporary session tokens can bypass two-factor authentication — Nextcloud Server, CVE-2026-45690 CVE-2026-45690 Medium
Cargo Malicious registry crates can overwrite dependency source — Cargo, CVE-2026-5223 CVE-2026-5223 Medium
Ruby DNS timing race can trigger a use-after-free — Ruby, CVE-2026-46727 CVE-2026-46727 High
urllib3 Cross-origin redirects can forward sensitive headers — urllib3, CVE-2026-44431 CVE-2026-44431 Medium
WebKit Thirteen-year WebKit flaw bypasses Content Security Policy — WebKit, CVE-2026-43660 CVE-2026-43660 High
WebKit WebKit input validation bypasses Content Security Policy — WebKit, CVE-2026-28907 CVE-2026-28907 High
WebKit WebKit data-protection flaw exposes sensitive user data — WebKit, CVE-2026-28958 CVE-2026-28958 Medium
Django Cached public pages can expose user sessions — Django, CVE-2026-35192 CVE-2026-35192 Medium
Spring Security Servlet-path matching can deactivate security controls — Spring Security, CVE-2026-22753 CVE-2026-22753 High
wolfSSL ECH server-name handling writes beyond allocated memory — wolfSSL, CVE-2026-5503 CVE-2026-5503 Critical
Django Forged admin forms can create unauthorized model instances — Django, CVE-2026-4292 CVE-2026-4292 Low
swift-crypto Short X-Wing keys trigger an out-of-bounds read — swift-crypto, CVE-2026-28815 CVE-2026-28815 High
XZ Utils Empty-index decoding can trigger heap buffer overflow — XZ Utils, CVE-2026-34743 CVE-2026-34743 Medium
Spring AI User-controlled filter keys enable SpEL code execution — Spring AI, CVE-2026-22738 CVE-2026-22738 Critical
Spring AI Filter keys enable Cypher injection in Neo4j stores — Spring AI, CVE-2026-22743 CVE-2026-22743 High
Claude Code Repository settings can skip the workspace trust prompt — Claude Code, CVE-2026-33068 CVE-2026-33068 High
OpenClaw Command mismatch can bypass execution approval — OpenClaw, CVE-2026-26325 CVE-2026-26325 High

How we handle disclosures

Findings are human-verified and coordinated with the affected maintainers before public disclosure. Each record identifies the affected project, the finding, and its public disclosure date.

Where available, records link to the technical research and maintainer references. A public disclosure date does not necessarily mean a fix is available in every release; consult the linked advisory or write-up for remediation and version details.