Search Results (5063 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-106557 2026-10-07 7.7 High
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-host data or internal network resources. This issue is fixed in versions 1.14.6 and 1.15.4 when pymdown-extensions 10.21.3 or later is also used, normally through mkdocs-techdocs-core 1.7.0 or later.
CVE-2026-106550 2026-10-07 7.5 High
Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the configuration key can write arbitrary properties to constructor.<key>, which walk() resolves to the global Object function. This allows overwriting core JavaScript methods such as Object.assign, leading to persistent process-wide failures and requiring a restart. The issue bypasses existing filters that only block constructor.prototype.* and __proto__.*. Exploitation requires an endpoint that forwards attacker-controlled keys into config.set().
CVE-2026-102255 1 Sonicwall 1 Sma1000 2026-10-07 10.0 Critical
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.
CVE-2026-101027 1 Gitea 1 Gitea 2026-10-07 7.7 High
When `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-network restrictions. A user who can start repository migrations and control the DNS of an allowed hostname could make it resolve to loopback or private addresses and bypass `ALLOW_LOCALNETWORKS = false`, reaching internal services from the Gitea server. Instances without `ALLOWED_DOMAINS` configured are not affected by this specific bypass.
CVE-2026-20362 2026-10-07 7.2 High
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated with the affected device.
CVE-2026-107273 1 Getgophish 1 Gophish 2026-10-07 4.3 Medium
Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site. Attackers can submit internal URLs, which the default dialer deny list does not block, to read service responses and enumerate internal hosts and ports through error messages.
CVE-2026-75036 1 Suse 2 Fleet, Rancher Fleet 2026-10-07 4.3 Medium
A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource can cause the Fleet controller to: - Disclose cluster metadata available to the templating context. - Reveal information about hosts reachable from the controller's network position. Because the disclosure channel is name resolution, it may remain effective in environments where outbound traffic is otherwise restricted. The disclosed information is limited to values exposed to the Fleet templating context and to name resolution results. Integrity and availability of managed clusters are not affected. This issue affects Fleet: from 0.12.0 before 0.12.19, from 0.13.0 before 0.13.15, from 0.14.0 before 0.14.10, from 0.15.0 before 0.15.6, and from 0.16.0 before 0.16.1.
CVE-2026-96400 1 Gitea 1 Gitea 2026-10-07 4.3 Medium
With `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validation could permit reserved and link-local addresses, such as `169.254.169.254`, even when `ALLOW_LOCALNETWORKS = false`. The local-network block list did not cover these ranges, and a hostname matching the allow list was accepted regardless of its resolved address. A user who can start migrations on such an instance could reach these addresses from the Gitea server; the default empty `ALLOWED_DOMAINS` configuration is not affected.
CVE-2026-97354 2026-10-07 4.1 Medium
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services.
CVE-2026-95265 1 Liufee 1 Feehicms 2026-10-07 7.5 High
Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor catchimage endpoint. The private-IP validation does not block loopback or link-local addresses, allowing an attacker to make the server probe internal HTTP services through response differences.
CVE-2026-87890 1 Djangoproject 1 Django 2026-10-07 5.3 Medium
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` values to cause the Django process to make network requests via a crafted VRT document referencing an external raster source. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank sicksec for reporting this issue.
CVE-2026-105790 1 Microsoft 1 Ufo 2026-10-07 6.4 Medium
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, authenticated device registration through /api/devices can supply a permitted attacker-controlled WebSocket endpoint while aip/transport/websocket.py applies pinned_addresses only to the initial destination. The pinned websockets.connect() client follows cross-origin redirects and opens a new TCP connection before Galaxy performs its post-handshake peer-IP validation, allowing WebSocket upgrade requests to internal hosts reachable from the server. The confirmed impact is the internal connection and handshake request, and does not establish arbitrary HTTP methods, response-body disclosure, a completed AIP session, or cloud metadata access. This issue is fixed in version 3.0.9.
CVE-2026-105804 1 Payloadcms 1 Payload 2026-10-07 N/A
Payload is a free and open source headless content management system. Payload versions from 3.0.0 before 3.90.0 and canary versions from 4.0.0-canary.0 before 4.0.0-canary.34 use a lower-than-recommended PBKDF2 work factor for password hashing, reducing the computational effort required to test recovered password hashes. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
CVE-2026-106100 1 Payloadcms 1 Payload 2026-10-07 7.1 High
Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field-level write access control does not permit that user to change. The Postgres and SQLite adapters are not affected. This issue is fixed in versions 3.87.0 and 4.0.0-canary.20.
CVE-2026-105863 1 Payloadcms 1 Payload 2026-10-07 N/A
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token issued at login. This issue is fixed in version 3.90.0.
CVE-2026-96890 1 Github 1 Enterprise Server 2026-10-07 N/A
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed a repository contributor to cause the appliance to issue requests to attacker-controlled internal hosts, which could be chained to achieve remote code execution on the appliance. The secret scanning validator for GCP service account credentials trusted the token endpoint embedded in a committed credential and issued a request to it without restricting the destination. Exploitation required an authenticated user with permission to push to a repository on an instance with GitHub Advanced Security and secret scanning validity checks enabled, a non-default configuration. This vulnerability affected GitHub Enterprise Server 3.20, 3.21, and 3.22 and was fixed in versions 3.20.9, 3.21.7, and 3.22.2. This vulnerability was reported through the GitHub Bug Bounty program.
CVE-2026-98322 1 Linux 1 Linux Kernel 2026-10-07 N/A
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_nat: fully initialise new_addr in netmap setup nft_nat_setup_netmap() builds the mapped address in an on-stack union nf_inet_addr. For an IPv4 mapping it writes only the 4-byte .ip member and the loop runs a single 32-bit iteration, but it then copies the whole 16-byte union into range->min_addr and range->max_addr, so the upper 12 bytes reach nf_nat_setup_info() uninitialised. KMSAN reports an uninit-value in nf_nat_setup_info() reached from nft_nat_eval(). The IPv6 path fills all 16 bytes and is not affected. Zero-initialise new_addr.
CVE-2026-89430 1 Gitea 1 Gitea 2026-10-07 N/A
Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to `git push`, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them.
CVE-2026-106455 2026-10-07 7.7 High
Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin configuration in techdocs. An authenticated attacker with control over a TechDocs source repository could cause a documentation build to retrieve and publish data from network locations reachable by the build environment. Exposure depends on deployment topology, build mode, and target endpoint protections. Modern cloud metadata services that require tokens or special headers are not directly accessible through the affected behavior. This issue is fixed in @backstage/plugin-techdocs-node versions 1.14.7 and 1.15.5.
CVE-2026-70357 1 Gitea 1 Gitea 2026-10-07 N/A
Gitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently resolves the hostname when connecting. An attacker who can start a migration and control the destination's DNS can change the address between validation and connection to reach a blocked internal address. The affected path is the Git clone operation; validation in the migration HTTP client's dialer does not protect the independently connecting Git subprocess.