Common Vulnerabilities and Exposures (CVE)

CVE-2026-87876

Sep 21, 2026 11:53:49 UTC

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain c...

CVE-2026-16118

Sep 21, 2026 11:50:57 UTC

A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data loc...

CVE-2026-94368

Sep 21, 2026 11:45:12 UTC

A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the service processes S3 presigned URLs using Signature Version 4 (SigV4). Due to imprope...

CVE-2026-93566

Sep 21, 2026 11:44:41 UTC

A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to ...

CVE-2026-85013

Sep 21, 2026 11:43:06 UTC

A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml`...

CVE-2026-89139

Sep 21, 2026 11:41:23 UTC

Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Worker ...

CVE-2026-87858

Sep 21, 2026 11:39:52 UTC

Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a single namespace could attach a completion callback whose URL h...

CVE-2026-65654

Sep 21, 2026 11:38:23 UTC

github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received in SWIM membership changes. A network peer ...

CVE-2025-57847

Sep 21, 2026 11:38:04 UTC

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an att...

CVE-2026-65653

Sep 21, 2026 11:36:47 UTC

github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks. The fragment reader left its chunk slice empty and then unconditionally selected the first element...

CVE-2026-65652

Sep 21, 2026 11:35:40 UTC

github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A network peer that can reach a listener can complete the standard initialization handshake and send a call request with an...

CVE-2026-65651

Sep 21, 2026 11:34:05 UTC

temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively trave...

CVE-2026-81627

Sep 21, 2026 11:32:47 UTC

A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over locked SMRA...

CVE-2026-16651

Sep 21, 2026 11:32:44 UTC

temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment does not check the -1 result returned by s...

CVE-2026-94210

Sep 21, 2026 11:30:13 UTC

A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. This manipulation causes cross site scripti...