Boletim Diário de Segurança

Busca em todas as edições

Agregado automaticamente, sem curadoria humana, a partir de fontes públicas: CISA KEV, NVD, GitHub Advisories, EQSTLab e CERT-EU. Cada alerta leva à sua fonte oficial.

1954 alertas em todas as edições, exibindo 1081–1110.

Alta · CVSS 7.5
NVD

CVE-2026-103055

AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts,...

Alta · CVSS 7.5
NVD

CVE-2026-13046

A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted...

Alta · CVSS 7.5
NVD

CVE-2026-103043

anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js event loop and...

Alta · CVSS 7.5
NVD

CVE-2026-103042

LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing...

Alta · CVSS 7.5
NVD

CVE-2026-91191

The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly...

Alta · CVSS 7.5
NVD

CVE-2026-84409

The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts...

Alta · CVSS 7.5
NVD

CVE-2026-94204

The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are...

Alta · CVSS 7.5
NVD

CVE-2026-102253

iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can...

Alta · CVSS 7.5código aberto
GitHub Advisories

CVE-2026-102281

Nest: Remote process termination via a deeply nested microservice message pattern

npm · @nestjs/microservices

A single message whose pattern is a deeply nested object terminates a NestJS microservice that uses the TCP or RabbitMQ transport. The server serialized the client-supplied pattern with JSON.stringify to derive the handler lookup key; on deeply nested input this throws RangeError: Maximum call stack size exceeded. The...

Alta · CVSS 7.5código aberto
GitHub Advisories

CVE-2026-102278

brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion

npm · brace-expansion

expand() recurses once per level of brace nesting. Deeply nested input exhausts the native stack and crashes the process. This is distinct from CVE-2026-14257 / GHSA-mh99-v99m-4gvg, which made the tail iterative (recursion on m.post, driven by how many groups are chained). Nesting depth drives a different recursion...

Alta · CVSS 7.5código aberto
GitHub Advisories

CVE-2026-102276

brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion

npm · brace-expansion

parseCommaParts() can exhaust the native stack and crash the process. There are two distinct ways to trigger it, both reachable from a single untrusted pattern string. This is the parsing-side counterpart to CVE-2026-14257 / GHSA-mh99-v99m-4gvg. That fix made expand() iterative and documented a constant-stack-depth...

Alta · CVSS 7.5código aberto
GitHub Advisories

CVE-2026-102599

Socket.IO: Engine.IO Protocol Revision Mismatch DoS

npm · engine.io

A denial-of-service vulnerability exists in Engine.IO / Socket.IO servers that allow transport upgrades. The Engine.IO protocol revision is negotiated during the initial handshake and stored on the session, but a newly-created transport, including a WebSocket upgrade transport, could independently derive a different...

Alta · CVSS 7.5código aberto
GitHub Advisories

Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service

npm · nodemailer

When addressparser finds no address by its strict reading, it falls back to pulling one out of the free text with /\s\b[^@\s]+@[^\s]+\b\s/. That pattern backtracks quadratically: [^@\s]+ is retried from every offset and rescans the run to the next @ each time. A single header value holding a long whitespace-free run...

Alta · CVSS 7.5
NVD

CVE-2026-67987

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or anomalous model response containing many unterminated <think> tags can cause excessive CPU consumption in two...

Alta · CVSS 7.5
NVD

CVE-2026-102327

Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Alta · CVSS 7.5
NVD

CVE-2026-100294

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation.

Alta · CVSS 7.5código aberto
GitHub Advisories

adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS)

npm · adm-zip

Denial of Service in adm-zip's async decompression API allows an unauthenticated attacker to crash the entire Node.js host process by supplying a single malformed ZIP file.

Alta · CVSS 7.5
NVD

CVE-2026-102823

Russh is a Rust SSH client and server library. Prior to 0.63.1, client_read_authenticated in russh/src/client/encrypted.rs forwards CHANNEL_DATA, CHANNEL_EXTENDED_DATA, CHANNEL_EOF, CHANNEL_CLOSE, CHANNEL_OPEN_FAILURE, CHANNEL_SUCCESS, CHANNEL_FAILURE, and CHANNEL_REQUEST subtypes exit-status, exit-signal, and...

Alta · CVSS 7.5
NVD

CVE-2026-95280

Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Alta · CVSS 7.5
NVD

CVE-2026-84440

IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.

Alta · CVSS 7.5
NVD

CVE-2026-102811

Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in...

Alta · CVSS 7.5
NVD

CVE-2026-102810

Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated attackers to read arbitrary files. The handle_request function in src/server.rs fails to reject .. segments after percent-decoding and joining the request path to the output folder,...

Alta · CVSS 7.5
NVD

CVE-2026-102758

The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake. The function reads the one-byte...

Alta · CVSS 7.5
NVD

CVE-2026-102728

Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malicious or malformed...

Alta · CVSS 7.5
NVD

CVE-2026-102796

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection. This issue affects Mediawiki - UserPageViewTracker Extension: from * before 1.46.1, 1.45.5, 1.43.10.

Alta · CVSS 7.5
NVD

CVE-2026-102634

SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users' requests...

Alta · CVSS 7.5
NVD

CVE-2026-100244

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows Excavation. This issue affects Mediawiki - CentralAuth Extension: from * before 1.46.1, 1.45.5, 1.43.10.

Alta · CVSS 7.5
NVD

CVE-2026-100242

Dependency on Vulnerable Third-Party Component and Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Excessive Allocation. This issue affects Mediawiki - DataTransfer Extension: from 1.46.0 before 1.47.0.

Alta · CVSS 7.5
NVD

CVE-2026-100241

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - EventBus Extension allows Excavation. This issue affects Mediawiki - EventBus Extension: 1.47.0-alpha.

Alta · CVSS 7.5
NVD

CVE-2026-84784

Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID...