New CVEs

topic · security/cve-published
DOC.
security/cve-published
REV.
2,974 evt
DATE.
08-JUN-2026
SCOPE.
custom
§01

about

Recently published CVE vulnerability records with CVSS scores (CIRCL).

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing 10 of 2,965 events in this window (2,974 total on topic). adjust the range or clear it with ALL.

range
iso 8601 utc
iso 8601 utc
01GHSA-676x-f7gg-47vcNetty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records{"url":"https://www.cve.org/CVERecord?id=GHSA-676x-f7gg-47vc","cvss":null,"cve_i…
EVENT. cms7kbxaID. cms7kbxamaxr7kh0cqv5ik33tSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-676x-f7gg-47vc",
  "cvss": null,
  "cve_id": "GHSA-676x-f7gg-47vc",
  "source": "circl",
  "summary": "Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/netty/netty/security/advisories/GHSA-676x-f7gg-47vc",
      "type": "WEB"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45674",
      "type": "ADVISORY"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26017",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26018",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26586",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
02GHSA-c2gf-v879-257jnetty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion{"url":"https://www.cve.org/CVERecord?id=GHSA-c2gf-v879-257j","cvss":null,"cve_i…
EVENT. cms7kbwsID. cms7kbwsbaxr5kh0cefhi9ilfSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-c2gf-v879-257j",
  "cvss": null,
  "cve_id": "GHSA-c2gf-v879-257j",
  "source": "circl",
  "summary": "netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j",
      "type": "WEB"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48043",
      "type": "ADVISORY"
    },
    {
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48043.json",
      "type": "WEB"
    },
    {
      "url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final",
      "type": "WEB"
    },
    {
      "url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
03GHSA-h2qv-fj59-j46jNetty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion{"url":"https://www.cve.org/CVERecord?id=GHSA-h2qv-fj59-j46j","cvss":null,"cve_i…
EVENT. cms7kbw9ID. cms7kbw9saxr3kh0c22yhcmosSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-h2qv-fj59-j46j",
  "cvss": null,
  "cve_id": "GHSA-h2qv-fj59-j46j",
  "source": "circl",
  "summary": "Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/netty/netty/security/advisories/GHSA-h2qv-fj59-j46j",
      "type": "WEB"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48059",
      "type": "ADVISORY"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26017",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26018",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26586",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
04GHSA-5mx2-7g4j-9m39GHSA-5mx2-7g4j-9m39{"url":"https://www.cve.org/CVERecord?id=GHSA-5mx2-7g4j-9m39","cvss":null,"cve_i…
EVENT. cms7kbvrID. cms7kbvrdaxr1kh0c2pmnkm9eSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-5mx2-7g4j-9m39",
  "cvss": null,
  "cve_id": "GHSA-5mx2-7g4j-9m39",
  "source": "circl",
  "summary": null,
  "severity": null,
  "references": [
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55654",
      "type": "ADVISORY"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:36759",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:47756",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:47757",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-55654",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
05GHSA-qcxp-gm7m-4j5vQuarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities{"url":"https://www.cve.org/CVERecord?id=GHSA-qcxp-gm7m-4j5v","cvss":null,"cve_i…
EVENT. cms7kbv8ID. cms7kbv8yaxqzkh0c22om5e5bSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-qcxp-gm7m-4j5v",
  "cvss": null,
  "cve_id": "GHSA-qcxp-gm7m-4j5v",
  "source": "circl",
  "summary": "Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/quarkusio/quarkus/security/advisories/GHSA-qcxp-gm7m-4j5v",
      "type": "WEB"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50559",
      "type": "ADVISORY"
    },
    {
      "url": "https://github.com/quarkusio/quarkus/commit/919b80017d85564143a845b38e9cca54aff5b3cc",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26017",
      "type": "WEB"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26018",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
06GHSA-rmj7-2vxq-3g9fjackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray){"url":"https://www.cve.org/CVERecord?id=GHSA-rmj7-2vxq-3g9f","cvss":null,"cve_i…
EVENT. cms7kbuqID. cms7kbuqnaxqxkh0crg9cyej0SRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-rmj7-2vxq-3g9f",
  "cvss": null,
  "cve_id": "GHSA-rmj7-2vxq-3g9f",
  "source": "circl",
  "summary": "jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f",
      "type": "WEB"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54513",
      "type": "ADVISORY"
    },
    {
      "url": "https://github.com/FasterXML/jackson-databind/issues/5983",
      "type": "WEB"
    },
    {
      "url": "https://github.com/FasterXML/jackson-databind/issues/5981",
      "type": "WEB"
    },
    {
      "url": "https://github.com/FasterXML/jackson-databind/pull/5984",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
07GHSA-4c8g-83qw-93j6fast-uri vulnerable to host confusion via failed IDN canonicalization{"url":"https://www.cve.org/CVERecord?id=GHSA-4c8g-83qw-93j6","cvss":null,"cve_i…
EVENT. cms7kbu8ID. cms7kbu8aaxqvkh0cdhanyiweSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-4c8g-83qw-93j6",
  "cvss": null,
  "cve_id": "GHSA-4c8g-83qw-93j6",
  "source": "circl",
  "summary": "fast-uri vulnerable to host confusion via failed IDN canonicalization",
  "severity": null,
  "references": [
    {
      "url": "https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6",
      "type": "WEB"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13676",
      "type": "ADVISORY"
    },
    {
      "url": "https://github.com/fastify/fast-uri/pull/188",
      "type": "WEB"
    },
    {
      "url": "https://github.com/fastify/fast-uri/commit/2a6d357a18a68e6d812824379fd3388a1ae50d05",
      "type": "WEB"
    },
    {
      "url": "https://github.com/fastify/fast-uri/commit/21ea1f9d70495c931f55dff893a8fa38f4f2e6bd",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
08GHSA-78ph-mc3q-52vvGHSA-78ph-mc3q-52vv{"url":"https://www.cve.org/CVERecord?id=GHSA-78ph-mc3q-52vv","cvss":null,"cve_i…
EVENT. cms7kbtqID. cms7kbtq2axqtkh0c69vbtp5kSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-78ph-mc3q-52vv",
  "cvss": null,
  "cve_id": "GHSA-78ph-mc3q-52vv",
  "source": "circl",
  "summary": null,
  "severity": null,
  "references": [
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64560",
      "type": "ADVISORY"
    },
    {
      "url": "https://git.kernel.org/stable/c/12a891c773aeb5823d63dbd0cb2ab931d6c21c9b",
      "type": "WEB"
    },
    {
      "url": "https://git.kernel.org/stable/c/67aa823e3e8c229c6d374df79c804f6721cb83b6",
      "type": "WEB"
    },
    {
      "url": "https://git.kernel.org/stable/c/6a7ecc25abe6f0fecc6e62a05096987200edbd02",
      "type": "WEB"
    },
    {
      "url": "https://git.kernel.org/stable/c/920f893f735e92ba3a1cd9256899a186b161928d",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
09GHSA-p8vm-xf6w-g5jxGHSA-p8vm-xf6w-g5jx{"url":"https://www.cve.org/CVERecord?id=GHSA-p8vm-xf6w-g5jx","cvss":null,"cve_i…
EVENT. cms7kbt7ID. cms7kbt7taxqrkh0c40xanac0SRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-p8vm-xf6w-g5jx",
  "cvss": null,
  "cve_id": "GHSA-p8vm-xf6w-g5jx",
  "source": "circl",
  "summary": null,
  "severity": null,
  "references": [
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4994",
      "type": "ADVISORY"
    },
    {
      "url": "https://git.kernel.org/stable/c/dc7a4bfde507ffe1d8bef49aba1322f1d20c2cb3",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
10GHSA-wm9c-mg5f-4mpgGHSA-wm9c-mg5f-4mpg{"url":"https://www.cve.org/CVERecord?id=GHSA-wm9c-mg5f-4mpg","cvss":null,"cve_i…
EVENT. cms7kbspID. cms7kbsphaxqpkh0cd3x0bnfnSRC. key:cmpxakb6
{
  "url": "https://www.cve.org/CVERecord?id=GHSA-wm9c-mg5f-4mpg",
  "cvss": null,
  "cve_id": "GHSA-wm9c-mg5f-4mpg",
  "source": "circl",
  "summary": null,
  "severity": null,
  "references": [
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2395",
      "type": "ADVISORY"
    },
    {
      "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0608",
      "type": "WEB"
    }
  ],
  "updated_at": null,
  "published_at": null
}
showing 1–10 of 2,965older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/cve-published/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/cve-published.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above