Common Vulnerabilities and Exposures (CVE)

CVE-2026-25949

Jun 30, 2026 12:08:15 UTC

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sending ...

CVE-2026-25960

Jun 30, 2026 12:08:15 UTC

vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from_url_async method due to inconsistent URL parsing behavior between the valida...

CVE-2026-25965

Jun 30, 2026 12:08:14 UTC

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolve...

CVE-2026-25985

Jun 30, 2026 12:08:14 UTC

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file containing an malicious element causes ImageMagick to attempt to allocate ~674 GB of...

CVE-2026-25990

Jun 30, 2026 12:08:14 UTC

Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.

CVE-2026-26007

Jun 30, 2026 12:08:13 UTC

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load...

CVE-2026-26017

Jun 30, 2026 12:08:13 UTC

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated bef...

CVE-2026-26018

Jun 30, 2026 12:08:13 UTC

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The ...

CVE-2026-26103

Jun 30, 2026 12:08:13 UTC

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned ud...

CVE-2026-26130

Jun 30, 2026 12:08:12 UTC

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVE-2026-26157

Jun 30, 2026 12:08:12 UTC

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directo...

CVE-2026-26158

Jun 30, 2026 12:08:12 UTC

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is ex...

CVE-2026-26171

Jun 30, 2026 12:08:12 UTC

Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.

CVE-2026-26200

Jun 30, 2026 12:08:11 UTC

HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially...

CVE-2026-26278

Jun 30, 2026 12:08:11 UTC

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of enti...