New CVEs

topic · security/cve-published
DOC.
security/cve-published
REV.
2,974 evt
DATE.
08-JUN-2026
§01

about

Recently published CVE vulnerability records with CVSS scores (CIRCL).

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing the 10 most recent of 2,974 total events on this topic. apply a date range to scope the list.

range
iso 8601 utc
iso 8601 utc
01GHSA-cg4g-m8jx-vjv2dssrf has an SSRF bypass with remove_at_symbol_in_string{"url":"https://www.cve.org/CVERecord?id=GHSA-cg4g-m8jx-vjv2","cvss":null,"cve_i…
EVENT. cms81knvID. cms81knvvb2i3kh0clihaya5mSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-cg4g-m8jx-vjv2",
  "cvss": null,
  "cve_id": "GHSA-cg4g-m8jx-vjv2",
  "source": "circl",
  "summary": "dssrf has an SSRF bypass with remove_at_symbol_in_string",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/HackingRepo/dssrf-js/security/advisories/GHSA-cg4g-m8jx-vjv2",
      "type": "WEB"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54722",
      "type": "ADVISORY"
    },
    {
      "url": "https://github.com/HackingRepo/dssrf-js/issues/97",
      "type": "WEB"
    },
    {
      "url": "https://github.com/HackingRepo/dssrf-js/pull/98",
      "type": "WEB"
    },
    {
      "url": "https://github.com/HackingRepo/dssrf-js/commit/9211f91bf532433a1a1b27d946571546a63664b3",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
02RUSTSEC-2026-0220Uint shift operations: incorrect overflow flags and truncated shift amounts{"url":"https://www.cve.org/CVERecord?id=RUSTSEC-2026-0220","cvss":null,"cve_id"…
EVENT. cms7x967ID. cms7x9671b17nkh0cbuoxty7iSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=RUSTSEC-2026-0220",
  "cvss": null,
  "cve_id": "RUSTSEC-2026-0220",
  "source": "circl",
  "summary": "Uint shift operations: incorrect overflow flags and truncated shift amounts",
  "severity": null,
  "references": [
    {
      "url": "https://crates.io/crates/ruint",
      "type": "PACKAGE"
    },
    {
      "url": "https://rustsec.org/advisories/RUSTSEC-2026-0220.html",
      "type": "ADVISORY"
    },
    {
      "url": "https://github.com/alloy-rs/ruint/pull/603",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
03GHSA-h3qp-gqrc-q736Spring Framework Open Redirect in Spring MVC and WebFlux{"url":"https://www.cve.org/CVERecord?id=GHSA-h3qp-gqrc-q736","cvss":null,"cve_i…
EVENT. cms7v577ID. cms7v577nb0k1kh0cpyit4lwmSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-h3qp-gqrc-q736",
  "cvss": null,
  "cve_id": "GHSA-h3qp-gqrc-q736",
  "source": "circl",
  "summary": "Spring Framework Open Redirect in Spring MVC and WebFlux",
  "severity": null,
  "references": [
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41844",
      "type": "ADVISORY"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework/commit/3aaec987651cf82fd4ed7e0ed9b3deddcdf58853",
      "type": "WEB"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework/commit/7add5243b9db13a9f8e765c8ab8545c8e8fe606b",
      "type": "WEB"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework",
      "type": "PACKAGE"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework/releases/tag/v6.2.19",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
04GHSA-9f52-rjqv-25qvSpring Framework Arbitrary Method Invocation in SpEL Expressions{"url":"https://www.cve.org/CVERecord?id=GHSA-9f52-rjqv-25qv","cvss":null,"cve_i…
EVENT. cms7v56oID. cms7v56oib0jzkh0cjg11p5axSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-9f52-rjqv-25qv",
  "cvss": null,
  "cve_id": "GHSA-9f52-rjqv-25qv",
  "source": "circl",
  "summary": "Spring Framework Arbitrary Method Invocation in SpEL Expressions",
  "severity": null,
  "references": [
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41852",
      "type": "ADVISORY"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework",
      "type": "PACKAGE"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework/releases/tag/v6.2.19",
      "type": "WEB"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework/releases/tag/v7.0.8",
      "type": "WEB"
    },
    {
      "url": "https://spring.io/security/cve-2026-41852",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
05GHSA-xr9x-r78c-5hrmActive Storage has possible arbitrary file read and remote code execution in Active Storage variant processing{"url":"https://www.cve.org/CVERecord?id=GHSA-xr9x-r78c-5hrm","cvss":null,"cve_i…
EVENT. cms7v564ID. cms7v564ab0jxkh0cwv2zu2waSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-xr9x-r78c-5hrm",
  "cvss": null,
  "cve_id": "GHSA-xr9x-r78c-5hrm",
  "source": "circl",
  "summary": "Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm",
      "type": "WEB"
    },
    {
      "url": "https://github.com/rails/rails/commit/1c01bb587206ee6eb0e1179c2cef96a6a47acb1e",
      "type": "WEB"
    },
    {
      "url": "https://github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5",
      "type": "WEB"
    },
    {
      "url": "https://github.com/rails/rails/commit/d79b7f4aa17dec8ce4960fef05733c8c0c7ef49a",
      "type": "WEB"
    },
    {
      "url": "https://github.com/rails/rails",
      "type": "PACKAGE"
    }
  ],
  "updated_at": null,
  "published_at": null
}
06GHSA-4hfh-6x8g-gwppSpring Framework Escalation via Session Fixation in WebFlux{"url":"https://www.cve.org/CVERecord?id=GHSA-4hfh-6x8g-gwpp","cvss":null,"cve_i…
EVENT. cms7oojdID. cms7oojdwayx9kh0cy1b466qpSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-4hfh-6x8g-gwpp",
  "cvss": null,
  "cve_id": "GHSA-4hfh-6x8g-gwpp",
  "source": "circl",
  "summary": "Spring Framework Escalation via Session Fixation in WebFlux",
  "severity": null,
  "references": [
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41839",
      "type": "ADVISORY"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework/issues/36742",
      "type": "WEB"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework/issues/36743",
      "type": "WEB"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework/commit/b8ddd2c690fe3f00bb5e3d9f913a37504aab49a0",
      "type": "WEB"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework/commit/d72da90d3a562632e2b565113813f7b4a31f8717",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
07GHSA-83f7-v6px-pp3hSpring Framework Denial of Service via Multipart Requests in WebFlux{"url":"https://www.cve.org/CVERecord?id=GHSA-83f7-v6px-pp3h","cvss":null,"cve_i…
EVENT. cms7ooiuID. cms7ooiuzayx7kh0cm3qi65i7SRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-83f7-v6px-pp3h",
  "cvss": null,
  "cve_id": "GHSA-83f7-v6px-pp3h",
  "source": "circl",
  "summary": "Spring Framework Denial of Service via Multipart Requests in WebFlux",
  "severity": null,
  "references": [
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41840",
      "type": "ADVISORY"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework",
      "type": "PACKAGE"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework/releases/tag/v6.2.19",
      "type": "WEB"
    },
    {
      "url": "https://github.com/spring-projects/spring-framework/releases/tag/v7.0.8",
      "type": "WEB"
    },
    {
      "url": "https://spring.io/security/cve-2026-41840",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
08GHSA-w2q5-6q6x-x959GHSA-w2q5-6q6x-x959{"url":"https://www.cve.org/CVERecord?id=GHSA-w2q5-6q6x-x959","cvss":null,"cve_i…
EVENT. cms7kbybID. cms7kbyb7axrbkh0c9ay6s3p1SRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-w2q5-6q6x-x959",
  "cvss": null,
  "cve_id": "GHSA-w2q5-6q6x-x959",
  "source": "circl",
  "summary": null,
  "severity": null,
  "references": [
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821",
      "type": "ADVISORY"
    },
    {
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:42142",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:42132",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:42082",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
09GHSA-5pvg-856g-cp85Netty has Insufficient Bailiwick Validation for NS Records{"url":"https://www.cve.org/CVERecord?id=GHSA-5pvg-856g-cp85","cvss":null,"cve_i…
EVENT. cms7kbxsID. cms7kbxsuaxr9kh0c4qms1rd7SRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-5pvg-856g-cp85",
  "cvss": null,
  "cve_id": "GHSA-5pvg-856g-cp85",
  "source": "circl",
  "summary": "Netty has Insufficient Bailiwick Validation for NS Records",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/netty/netty/security/advisories/GHSA-5pvg-856g-cp85",
      "type": "WEB"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47691",
      "type": "ADVISORY"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26017",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26018",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26586",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
10GHSA-676x-f7gg-47vcNetty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records{"url":"https://www.cve.org/CVERecord?id=GHSA-676x-f7gg-47vc","cvss":null,"cve_i…
EVENT. cms7kbxaID. cms7kbxamaxr7kh0cqv5ik33tSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-676x-f7gg-47vc",
  "cvss": null,
  "cve_id": "GHSA-676x-f7gg-47vc",
  "source": "circl",
  "summary": "Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/netty/netty/security/advisories/GHSA-676x-f7gg-47vc",
      "type": "WEB"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45674",
      "type": "ADVISORY"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26017",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26018",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26586",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
showing 1–10 of 2,974older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/cve-published/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/cve-published.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above