@CVEnew

Official account maintained by the CVE™ Program to notify the community of new CVE IDs. Posts contain abbreviated details. Full CVE Records on https://nitter.cf/t.co/ALn4YvUtom

Joined January 2017
CVE-2026-93302 MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT … cve.org/CVERecord?id=CVE-202…
699
CVE-2026-89136 When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited server_cert_type=RawPublicKey which allowed a m… cve.org/CVERecord?id=CVE-202…
604
CVE-2026-89135 A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling co… cve.org/CVERecord?id=CVE-202…
628
CVE-2026-89134 A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName name-constraint check. The CN-as-DNS f… cve.org/CVERecord?id=CVE-202…
523
CVE-2026-89133 wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there i… cve.org/CVERecord?id=CVE-202…
634
CVE-2026-89102 In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery… cve.org/CVERecord?id=CVE-202…
652
CVE-2026-15442 In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after … cve.org/CVERecord?id=CVE-202…
480
CVE-2026-100866 onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection.… cve.org/CVERecord?id=CVE-202…
600
CVE-2026-100867 spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt. Attackers can emb… cve.org/CVERecord?id=CVE-202…
562
CVE-2026-100868 Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on… cve.org/CVERecord?id=CVE-202…
448
CVE-2026-100869 Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders… cve.org/CVERecord?id=CVE-202…
449
CVE-2026-100870 Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allow… cve.org/CVERecord?id=CVE-202…
441
CVE-2026-100871 Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endp… cve.org/CVERecord?id=CVE-202…
481
CVE-2026-100872 Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after … cve.org/CVERecord?id=CVE-202…
568
CVE-2026-101032 navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Attackers can inject shell metacharacters throug… cve.org/CVERecord?id=CVE-202…
460
CVE-2026-101033 KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate c… cve.org/CVERecord?id=CVE-202…
1
1
509
CVE-2026-101041 The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-time-of-use (TOCTOU) race condition in t… cve.org/CVERecord?id=CVE-202…
469
CVE-2026-100883 A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing… cve.org/CVERecord?id=CVE-202…
682
CVE-2026-100884 A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Confi… cve.org/CVERecord?id=CVE-202…
461
CVE-2026-100885 A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.p… cve.org/CVERecord?id=CVE-202…
521