New CVEs
topic · security/cve-published
§01
about
Recently published CVE vulnerability records with CVSS scores (CIRCL).
§02
recent events
LIVElast event 0s ago0 evt / 1h
showing 10 of 2,965 events in this window (2,974 total on topic). adjust the range or clear it with ALL.
range
01GHSA-676x-f7gg-47vcNetty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records{"url":"https://www.cve.org/CVERecord?id=GHSA-676x-f7gg-47vc","cvss":null,"cve_i…
EVENT. cms7kbxaID. cms7kbxamaxr7kh0cqv5ik33tSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-676x-f7gg-47vc",
"cvss": null,
"cve_id": "GHSA-676x-f7gg-47vc",
"source": "circl",
"summary": "Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records",
"severity": null,
"references": [
{
"url": "https://github.com/netty/netty/security/advisories/GHSA-676x-f7gg-47vc",
"type": "WEB"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45674",
"type": "ADVISORY"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:26017",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:26018",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:26586",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}02GHSA-c2gf-v879-257jnetty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion{"url":"https://www.cve.org/CVERecord?id=GHSA-c2gf-v879-257j","cvss":null,"cve_i…
EVENT. cms7kbwsID. cms7kbwsbaxr5kh0cefhi9ilfSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-c2gf-v879-257j",
"cvss": null,
"cve_id": "GHSA-c2gf-v879-257j",
"source": "circl",
"summary": "netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion",
"severity": null,
"references": [
{
"url": "https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j",
"type": "WEB"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48043",
"type": "ADVISORY"
},
{
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48043.json",
"type": "WEB"
},
{
"url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final",
"type": "WEB"
},
{
"url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}03GHSA-h2qv-fj59-j46jNetty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion{"url":"https://www.cve.org/CVERecord?id=GHSA-h2qv-fj59-j46j","cvss":null,"cve_i…
EVENT. cms7kbw9ID. cms7kbw9saxr3kh0c22yhcmosSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-h2qv-fj59-j46j",
"cvss": null,
"cve_id": "GHSA-h2qv-fj59-j46j",
"source": "circl",
"summary": "Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion",
"severity": null,
"references": [
{
"url": "https://github.com/netty/netty/security/advisories/GHSA-h2qv-fj59-j46j",
"type": "WEB"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48059",
"type": "ADVISORY"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:26017",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:26018",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:26586",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}04GHSA-5mx2-7g4j-9m39GHSA-5mx2-7g4j-9m39{"url":"https://www.cve.org/CVERecord?id=GHSA-5mx2-7g4j-9m39","cvss":null,"cve_i…
EVENT. cms7kbvrID. cms7kbvrdaxr1kh0c2pmnkm9eSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-5mx2-7g4j-9m39",
"cvss": null,
"cve_id": "GHSA-5mx2-7g4j-9m39",
"source": "circl",
"summary": null,
"severity": null,
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55654",
"type": "ADVISORY"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:36759",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:47756",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:47757",
"type": "WEB"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2026-55654",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}05GHSA-qcxp-gm7m-4j5vQuarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities{"url":"https://www.cve.org/CVERecord?id=GHSA-qcxp-gm7m-4j5v","cvss":null,"cve_i…
EVENT. cms7kbv8ID. cms7kbv8yaxqzkh0c22om5e5bSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-qcxp-gm7m-4j5v",
"cvss": null,
"cve_id": "GHSA-qcxp-gm7m-4j5v",
"source": "circl",
"summary": "Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities",
"severity": null,
"references": [
{
"url": "https://github.com/quarkusio/quarkus/security/advisories/GHSA-qcxp-gm7m-4j5v",
"type": "WEB"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50559",
"type": "ADVISORY"
},
{
"url": "https://github.com/quarkusio/quarkus/commit/919b80017d85564143a845b38e9cca54aff5b3cc",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:26017",
"type": "WEB"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:26018",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}06GHSA-rmj7-2vxq-3g9fjackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray){"url":"https://www.cve.org/CVERecord?id=GHSA-rmj7-2vxq-3g9f","cvss":null,"cve_i…
EVENT. cms7kbuqID. cms7kbuqnaxqxkh0crg9cyej0SRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-rmj7-2vxq-3g9f",
"cvss": null,
"cve_id": "GHSA-rmj7-2vxq-3g9f",
"source": "circl",
"summary": "jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)",
"severity": null,
"references": [
{
"url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f",
"type": "WEB"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54513",
"type": "ADVISORY"
},
{
"url": "https://github.com/FasterXML/jackson-databind/issues/5983",
"type": "WEB"
},
{
"url": "https://github.com/FasterXML/jackson-databind/issues/5981",
"type": "WEB"
},
{
"url": "https://github.com/FasterXML/jackson-databind/pull/5984",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}07GHSA-4c8g-83qw-93j6fast-uri vulnerable to host confusion via failed IDN canonicalization{"url":"https://www.cve.org/CVERecord?id=GHSA-4c8g-83qw-93j6","cvss":null,"cve_i…
EVENT. cms7kbu8ID. cms7kbu8aaxqvkh0cdhanyiweSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-4c8g-83qw-93j6",
"cvss": null,
"cve_id": "GHSA-4c8g-83qw-93j6",
"source": "circl",
"summary": "fast-uri vulnerable to host confusion via failed IDN canonicalization",
"severity": null,
"references": [
{
"url": "https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6",
"type": "WEB"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13676",
"type": "ADVISORY"
},
{
"url": "https://github.com/fastify/fast-uri/pull/188",
"type": "WEB"
},
{
"url": "https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05",
"type": "WEB"
},
{
"url": "https://github.com/fastify/fast-uri/commit/21ea1f9d70495c931f55dff893a8fa38f4f2e6bd",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}08GHSA-78ph-mc3q-52vvGHSA-78ph-mc3q-52vv{"url":"https://www.cve.org/CVERecord?id=GHSA-78ph-mc3q-52vv","cvss":null,"cve_i…
EVENT. cms7kbtqID. cms7kbtq2axqtkh0c69vbtp5kSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-78ph-mc3q-52vv",
"cvss": null,
"cve_id": "GHSA-78ph-mc3q-52vv",
"source": "circl",
"summary": null,
"severity": null,
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64560",
"type": "ADVISORY"
},
{
"url": "https://git.kernel.org/stable/c/12a891c773aeb5823d63dbd0cb2ab931d6c21c9b",
"type": "WEB"
},
{
"url": "https://git.kernel.org/stable/c/67aa823e3e8c229c6d374df79c804f6721cb83b6",
"type": "WEB"
},
{
"url": "https://git.kernel.org/stable/c/6a7ecc25abe6f0fecc6e62a05096987200edbd02",
"type": "WEB"
},
{
"url": "https://git.kernel.org/stable/c/920f893f735e92ba3a1cd9256899a186b161928d",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}09GHSA-p8vm-xf6w-g5jxGHSA-p8vm-xf6w-g5jx{"url":"https://www.cve.org/CVERecord?id=GHSA-p8vm-xf6w-g5jx","cvss":null,"cve_i…
EVENT. cms7kbt7ID. cms7kbt7taxqrkh0c40xanac0SRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-p8vm-xf6w-g5jx",
"cvss": null,
"cve_id": "GHSA-p8vm-xf6w-g5jx",
"source": "circl",
"summary": null,
"severity": null,
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4994",
"type": "ADVISORY"
},
{
"url": "https://git.kernel.org/stable/c/dc7a4bfde507ffe1d8bef49aba1322f1d20c2cb3",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}10GHSA-wm9c-mg5f-4mpgGHSA-wm9c-mg5f-4mpg{"url":"https://www.cve.org/CVERecord?id=GHSA-wm9c-mg5f-4mpg","cvss":null,"cve_i…
EVENT. cms7kbspID. cms7kbsphaxqpkh0cd3x0bnfnSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=GHSA-wm9c-mg5f-4mpg",
"cvss": null,
"cve_id": "GHSA-wm9c-mg5f-4mpg",
"source": "circl",
"summary": null,
"severity": null,
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2395",
"type": "ADVISORY"
},
{
"url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0608",
"type": "WEB"
}
],
"updated_at": null,
"published_at": null
}showing 1–10 of 2,965older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/cve-published/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/cve-published.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above