Product CompCert x86-64 switch miscompilation can read beyond its jump table — CompCert, COMPCERT-595 CVE — No CVE identifier Severity Unrated Disclosed September 16, 2026 Product Seagate openSeaChest SCSI defect count can overflow the defect-list allocation — Seagate openSeaChest, CVE-2026-10717 CVE CVE-2026-10717 Severity Low Disclosed August 24, 2026 Product Seagate openSeaChest NVMe deallocate loop can write a 257th descriptor — Seagate openSeaChest, CVE-2026-10718 CVE CVE-2026-10718 Severity Medium Disclosed August 24, 2026 Product Seagate openSeaChest FLBAS index can write beyond allocated format entries — Seagate openSeaChest, CVE-2026-10719 CVE CVE-2026-10719 Severity Low Disclosed August 24, 2026 Product CompCert Dropped tag binding can produce the wrong C struct layout — CompCert, COMPCERT-0375C18 CVE — No CVE identifier Severity Medium Disclosed August 18, 2026 Product CompCert Win64 backend can corrupt nonvolatile XMM registers — CompCert, COMPCERT-584 CVE — No CVE identifier Severity Medium Disclosed August 18, 2026 Product CompCert Newlines in filenames can inject ARM assembly — CompCert, COMPCERT-586 CVE — No CVE identifier Severity High Disclosed August 18, 2026 Product Node.js Stale SQLite iterators can replay bound writes — Node.js, CVE-2026-58041 CVE CVE-2026-58041 Severity Medium Disclosed August 11, 2026 Product Node.js Large DNS responses can abort Node.js workers — Node.js, CVE-2026-58042 CVE CVE-2026-58042 Severity Medium Disclosed August 11, 2026 Product Adobe Content Credentials Improper input validation can permit limited unauthorized writes — Adobe Content Credentials, CVE-2026-71390 CVE CVE-2026-71390 Severity Medium Disclosed August 11, 2026 Product Ruby Prism UTF-8 stream reads can overflow Prism's fixed stack buffer — Ruby Prism, PRISM-4172 CVE — No CVE identifier Severity High Disclosed August 4, 2026 Product RabbitMQ Direct-reply-to bindings enable cross-tenant injection — RabbitMQ, CVE-2026-57215 CVE CVE-2026-57215 Severity High Disclosed June 24, 2026 Product RabbitMQ Proxy handling bypasses loopback-only authentication — RabbitMQ, CVE-2026-57216 CVE CVE-2026-57216 Severity Medium Disclosed June 24, 2026 Product RabbitMQ Topic permissions fail open during metadata errors — RabbitMQ, CVE-2026-57217 CVE CVE-2026-57217 Severity High Disclosed June 24, 2026 Product RabbitMQ OAuth consumers retain access after token expiry — RabbitMQ, CVE-2026-57218 CVE CVE-2026-57218 Severity Medium Disclosed June 24, 2026 Product Node.js Unicode hostname separators bypass TLS wildcard depth — Node.js, CVE-2026-48618 CVE CVE-2026-48618 Severity High Disclosed June 18, 2026 Product Node.js Mixed-case SNI can bypass mTLS trust policies — Node.js, CVE-2026-48928 CVE CVE-2026-48928 Severity Medium Disclosed June 18, 2026 Product Node.js Embedded NUL bytes can silently rebind TLS authority — Node.js, CVE-2026-48930 CVE CVE-2026-48930 Severity Medium Disclosed June 18, 2026 Product Nextcloud Server Temporary session tokens can bypass two-factor authentication — Nextcloud Server, CVE-2026-45690 CVE CVE-2026-45690 Severity Medium Disclosed June 1, 2026 Product Cargo Malicious registry crates can overwrite dependency source — Cargo, CVE-2026-5223 CVE CVE-2026-5223 Severity Medium Disclosed May 25, 2026 Product Ruby DNS timing race can trigger a use-after-free — Ruby, CVE-2026-46727 CVE CVE-2026-46727 Severity High Disclosed May 20, 2026 Product urllib3 Cross-origin redirects can forward sensitive headers — urllib3, CVE-2026-44431 CVE CVE-2026-44431 Severity Medium Disclosed May 13, 2026 Product WebKit Thirteen-year WebKit flaw bypasses Content Security Policy — WebKit, CVE-2026-43660 CVE CVE-2026-43660 Severity High Disclosed May 12, 2026 Product WebKit WebKit input validation bypasses Content Security Policy — WebKit, CVE-2026-28907 CVE CVE-2026-28907 Severity High Disclosed May 11, 2026 Product WebKit WebKit data-protection flaw exposes sensitive user data — WebKit, CVE-2026-28958 CVE CVE-2026-28958 Severity Medium Disclosed May 11, 2026 Product Django Cached public pages can expose user sessions — Django, CVE-2026-35192 CVE CVE-2026-35192 Severity Medium Disclosed May 5, 2026 Product Spring Security Servlet-path matching can deactivate security controls — Spring Security, CVE-2026-22753 CVE CVE-2026-22753 Severity High Disclosed April 22, 2026 Product wolfSSL ECH server-name handling writes beyond allocated memory — wolfSSL, CVE-2026-5503 CVE CVE-2026-5503 Severity Critical Disclosed April 9, 2026 Product Django Forged admin forms can create unauthorized model instances — Django, CVE-2026-4292 CVE CVE-2026-4292 Severity Low Disclosed April 7, 2026 Product swift-crypto Short X-Wing keys trigger an out-of-bounds read — swift-crypto, CVE-2026-28815 CVE CVE-2026-28815 Severity High Disclosed April 2, 2026 Product XZ Utils Empty-index decoding can trigger heap buffer overflow — XZ Utils, CVE-2026-34743 CVE CVE-2026-34743 Severity Medium Disclosed April 2, 2026 Product Spring AI User-controlled filter keys enable SpEL code execution — Spring AI, CVE-2026-22738 CVE CVE-2026-22738 Severity Critical Disclosed March 27, 2026 Product Spring AI Filter keys enable Cypher injection in Neo4j stores — Spring AI, CVE-2026-22743 CVE CVE-2026-22743 Severity High Disclosed March 27, 2026 Product Claude Code Repository settings can skip the workspace trust prompt — Claude Code, CVE-2026-33068 CVE CVE-2026-33068 Severity High Disclosed March 20, 2026 Product OpenClaw Command mismatch can bypass execution approval — OpenClaw, CVE-2026-26325 CVE CVE-2026-26325 Severity High Disclosed February 19, 2026