[{"id":"cms80hqqqb279kh0cl31czcpj","channel":"security","topic":"github-advisories","title":"CRITICAL: AWS Amplify Studio UI Component Properties Has an Input Validation Issue","summary":"critical severity · @aws-amplify/codegen-ui-react · CVE-2025-4318","payload":{"cve":"CVE-2025-4318","url":"https://github.com/advisories/GHSA-hf3j-86p7-mfw8","cwes":["CWE-95"],"source":"github_advisory_database","ghsa_id":"GHSA-hf3j-86p7-mfw8","summary":"AWS Amplify Studio UI Component Properties Has an Input Validation Issue","severity":"critical","cvss_score":null,"ecosystems":["npm"],"references":["https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-hf3j-86p7-mfw8","https://nvd.nist.gov/vuln/detail/CVE-2025-4318","https://github.com/aws-amplify/amplify-codegen-ui/commit/ca98c38b7c3d69ae7c94d2f62b51e32e8165dae6","https://aws.amazon.com/security/security-bulletins/AWS-2025-010","https://blog.securelayer7.net/cve-2025-4318-aws-amplify-rce"],"updated_at":"2026-07-30T20:57:25.000Z","cvss_vector":null,"published_at":"2026-07-30T20:57:24.000Z","withdrawn_at":null,"affected_packages":[{"name":"@aws-amplify/codegen-ui-react","ecosystem":"npm","first_patched":"2.20.3","vulnerable_range":"<= 2.20.2"}]},"public_metadata":null,"published_at":"2026-07-30T21:14:32.738Z"},{"id":"cms7w7k1eb0x9kh0cy997qoum","channel":"security","topic":"github-advisories","title":"CRITICAL: Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing","summary":"critical severity · activestorage, activestorage, activestorage · CVE-2026-66066","payload":{"cve":"CVE-2026-66066","url":"https://github.com/advisories/GHSA-xr9x-r78c-5hrm","cwes":["CWE-1188"],"source":"github_advisory_database","ghsa_id":"GHSA-xr9x-r78c-5hrm","summary":"Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing","severity":"critical","cvss_score":null,"ecosystems":["rubygems"],"references":["https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm","https://github.com/rails/rails/commit/1c01bb587206ee6eb0e1179c2cef96a6a47acb1e","https://github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5","https://github.com/rails/rails/commit/d79b7f4aa17dec8ce4960fef05733c8c0c7ef49a","https://github.com/rails/rails/releases/tag/v7.2.3.2"],"updated_at":"2026-07-30T18:23:34.000Z","cvss_vector":null,"published_at":"2026-07-30T18:23:33.000Z","withdrawn_at":null,"affected_packages":[{"name":"activestorage","ecosystem":"rubygems","first_patched":"7.2.3.2","vulnerable_range":"< 7.2.3.2"},{"name":"activestorage","ecosystem":"rubygems","first_patched":"8.0.5.1","vulnerable_range":">= 8.0.0.beta1, < 8.0.5.1"},{"name":"activestorage","ecosystem":"rubygems","first_patched":"8.1.3.1","vulnerable_range":">= 8.1.0.beta1, < 8.1.3.1"}]},"public_metadata":null,"published_at":"2026-07-30T19:14:39.027Z"},{"id":"cms7rx2h8azpxkh0c28n6ebwa","channel":"security","topic":"github-advisories","title":"HIGH: dssrf has an SSRF bypass with remove_at_symbol_in_string","summary":"high severity · dssrf · CVE-2026-54722","payload":{"cve":"CVE-2026-54722","url":"https://github.com/advisories/GHSA-cg4g-m8jx-vjv2","cwes":["CWE-76"],"source":"github_advisory_database","ghsa_id":"GHSA-cg4g-m8jx-vjv2","summary":"dssrf has an SSRF bypass with remove_at_symbol_in_string","severity":"high","cvss_score":null,"ecosystems":["npm"],"references":["https://github.com/HackingRepo/dssrf-js/security/advisories/GHSA-cg4g-m8jx-vjv2","https://github.com/HackingRepo/dssrf-js/issues/97","https://github.com/HackingRepo/dssrf-js/pull/98","https://github.com/HackingRepo/dssrf-js/commit/9211f91bf532433a1a1b27d946571546a63664b3","https://github.com/advisories/GHSA-cg4g-m8jx-vjv2"],"updated_at":"2026-07-30T16:26:54.000Z","cvss_vector":null,"published_at":"2026-07-30T16:26:52.000Z","withdrawn_at":null,"affected_packages":[{"name":"dssrf","ecosystem":"npm","first_patched":"1.0.4","vulnerable_range":"<= 1.0.3"}]},"public_metadata":null,"published_at":"2026-07-30T17:14:31.244Z"},{"id":"cms7rx1v9azptkh0cs871r5cq","channel":"security","topic":"github-advisories","title":"LOW: MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure","summary":"low severity · msgpack · CVE-2026-54522","payload":{"cve":"CVE-2026-54522","url":"https://github.com/advisories/GHSA-4mrv-5p47-p938","cwes":["CWE-416"],"source":"github_advisory_database","ghsa_id":"GHSA-4mrv-5p47-p938","summary":"MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure","severity":"low","cvss_score":null,"ecosystems":["rubygems"],"references":["https://github.com/msgpack/msgpack-ruby/security/advisories/GHSA-4mrv-5p47-p938","https://github.com/msgpack/msgpack-ruby/commit/5627d71606b565641d2dd501b82aae862f4abe90","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/msgpack/CVE-2026-54522.yml","https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-54522","https://github.com/advisories/GHSA-4mrv-5p47-p938"],"updated_at":"2026-07-30T16:33:13.000Z","cvss_vector":null,"published_at":"2026-07-30T16:33:12.000Z","withdrawn_at":null,"affected_packages":[{"name":"msgpack","ecosystem":"rubygems","first_patched":"1.8.2","vulnerable_range":"<= 1.8.1"}]},"public_metadata":null,"published_at":"2026-07-30T17:14:30.453Z"},{"id":"cms7nn3gzayndkh0c7g3vhedt","channel":"security","topic":"github-advisories","title":"HIGH: OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)","summary":"high severity · github.com/OliveTin/OliveTin · CVE-2026-67437","payload":{"cve":"CVE-2026-67437","url":"https://github.com/advisories/GHSA-xpxj-f2fm-rqch","cwes":["CWE-400","CWE-401","CWE-770"],"source":"github_advisory_database","ghsa_id":"GHSA-xpxj-f2fm-rqch","summary":"OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)","severity":"high","cvss_score":7.5,"ecosystems":["go"],"references":["https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xpxj-f2fm-rqch","https://nvd.nist.gov/vuln/detail/CVE-2026-67437","https://github.com/OliveTin/OliveTin/commit/ec114e95d297b806c3ca0c37bc139b3c9c517b3f","https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0","https://github.com/advisories/GHSA-xpxj-f2fm-rqch"],"updated_at":"2026-07-30T14:24:55.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","published_at":"2026-07-30T14:24:53.000Z","withdrawn_at":null,"affected_packages":[{"name":"github.com/OliveTin/OliveTin","ecosystem":"go","first_patched":"0.0.0-20260708075951-ec114e95d297","vulnerable_range":">= 0.0.0-20251024001301-45f9c18bc3ee, < 0.0.0-20260708075951-ec114e95d297"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:47.507Z"},{"id":"cms7nn2xjaynbkh0c6b1v4hvq","channel":"security","topic":"github-advisories","title":"MEDIUM: OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output","summary":"medium severity · github.com/OliveTin/OliveTin · CVE-2026-67439","payload":{"cve":"CVE-2026-67439","url":"https://github.com/advisories/GHSA-jm28-2wcr-qf3h","cwes":["CWE-863"],"source":"github_advisory_database","ghsa_id":"GHSA-jm28-2wcr-qf3h","summary":"OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output","severity":"medium","cvss_score":4.3,"ecosystems":["go"],"references":["https://github.com/OliveTin/OliveTin/security/advisories/GHSA-jm28-2wcr-qf3h","https://nvd.nist.gov/vuln/detail/CVE-2026-67439","https://github.com/OliveTin/OliveTin/commit/e421780c9885aa5024d2f47b4ed4898f2f18eb90","https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0","https://github.com/advisories/GHSA-jm28-2wcr-qf3h"],"updated_at":"2026-07-30T14:25:21.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","published_at":"2026-07-30T14:25:20.000Z","withdrawn_at":null,"affected_packages":[{"name":"github.com/OliveTin/OliveTin","ecosystem":"go","first_patched":"0.0.0-20260708085316-e421780c9885","vulnerable_range":"< 0.0.0-20260708085316-e421780c9885"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:46.807Z"},{"id":"cms7nn2e9ayn9kh0col303ae1","channel":"security","topic":"github-advisories","title":"MEDIUM: OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check","summary":"medium severity · github.com/OliveTin/OliveTin · CVE-2026-67438","payload":{"cve":"CVE-2026-67438","url":"https://github.com/advisories/GHSA-xc5w-4v5w-7x65","cwes":["CWE-78"],"source":"github_advisory_database","ghsa_id":"GHSA-xc5w-4v5w-7x65","summary":"OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check","severity":"medium","cvss_score":6.6,"ecosystems":["go"],"references":["https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xc5w-4v5w-7x65","https://nvd.nist.gov/vuln/detail/CVE-2026-67438","https://github.com/OliveTin/OliveTin/commit/995ff79736f2bccc364448a3ece84087b550b232","https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0","https://github.com/advisories/GHSA-xc5w-4v5w-7x65"],"updated_at":"2026-07-30T14:31:15.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","published_at":"2026-07-30T14:31:12.000Z","withdrawn_at":null,"affected_packages":[{"name":"github.com/OliveTin/OliveTin","ecosystem":"go","first_patched":"0.0.0-20260708084548-995ff79736f2","vulnerable_range":">= 0.0.0-20251025234746-ef5a67e7b8ea, < 0.0.0-20260708084548-995ff79736f2"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:46.113Z"},{"id":"cms7nn1uwayn7kh0c299xyydr","channel":"security","topic":"github-advisories","title":"MEDIUM: MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection","summary":"medium severity · mcp · CVE-2026-63118","payload":{"cve":"CVE-2026-63118","url":"https://github.com/advisories/GHSA-rjr6-rcgv-9m7m","cwes":["CWE-346","CWE-350"],"source":"github_advisory_database","ghsa_id":"GHSA-rjr6-rcgv-9m7m","summary":"MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection","severity":"medium","cvss_score":null,"ecosystems":["rubygems"],"references":["https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-rjr6-rcgv-9m7m","https://nvd.nist.gov/vuln/detail/CVE-2026-63118","https://github.com/modelcontextprotocol/ruby-sdk/commit/ba543083a7594e7892b29464b89091816446ff7a","https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0","https://github.com/advisories/GHSA-rjr6-rcgv-9m7m"],"updated_at":"2026-07-30T14:41:42.000Z","cvss_vector":null,"published_at":"2026-07-30T14:41:39.000Z","withdrawn_at":null,"affected_packages":[{"name":"mcp","ecosystem":"rubygems","first_patched":"0.23.0","vulnerable_range":"<= 0.22.0"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:45.417Z"},{"id":"cms7nn1bcayn5kh0cqn2eb0k0","channel":"security","topic":"github-advisories","title":"MEDIUM: MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)","summary":"medium severity · mcp · CVE-2026-63119","payload":{"cve":"CVE-2026-63119","url":"https://github.com/advisories/GHSA-7683-3w9x-ch42","cwes":["CWE-400","CWE-770"],"source":"github_advisory_database","ghsa_id":"GHSA-7683-3w9x-ch42","summary":"MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)","severity":"medium","cvss_score":6.2,"ecosystems":["rubygems"],"references":["https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-7683-3w9x-ch42","https://nvd.nist.gov/vuln/detail/CVE-2026-63119","https://github.com/modelcontextprotocol/ruby-sdk/commit/267b8fa6285453525c81ce43db6b7dcd7a8a8c2f","https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0","https://github.com/advisories/GHSA-7683-3w9x-ch42"],"updated_at":"2026-07-30T14:41:58.000Z","cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","published_at":"2026-07-30T14:41:58.000Z","withdrawn_at":null,"affected_packages":[{"name":"mcp","ecosystem":"rubygems","first_patched":"0.23.0","vulnerable_range":"<= 0.22.0"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:44.712Z"},{"id":"cms7nn0rwayn3kh0c1tluceu6","channel":"security","topic":"github-advisories","title":"MEDIUM: MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood","summary":"medium severity · mcp · CVE-2026-67430","payload":{"cve":"CVE-2026-67430","url":"https://github.com/advisories/GHSA-52jp-gj8w-j6xh","cwes":["CWE-401","CWE-770"],"source":"github_advisory_database","ghsa_id":"GHSA-52jp-gj8w-j6xh","summary":"MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood","severity":"medium","cvss_score":5.3,"ecosystems":["rubygems"],"references":["https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-52jp-gj8w-j6xh","https://nvd.nist.gov/vuln/detail/CVE-2026-67430","https://github.com/modelcontextprotocol/ruby-sdk/commit/afb968c468c178c4d3294b423fcce250621692f4","https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0","https://github.com/advisories/GHSA-52jp-gj8w-j6xh"],"updated_at":"2026-07-30T14:43:29.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","published_at":"2026-07-30T14:43:29.000Z","withdrawn_at":null,"affected_packages":[{"name":"mcp","ecosystem":"rubygems","first_patched":"0.23.0","vulnerable_range":"<= 0.22.0"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:44.012Z"},{"id":"cms7nn08gayn1kh0cgfoa2n4x","channel":"security","topic":"github-advisories","title":"HIGH: MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport","summary":"high severity · mcp · CVE-2026-67432","payload":{"cve":"CVE-2026-67432","url":"https://github.com/advisories/GHSA-h669-8m4g-r2hc","cwes":["CWE-770"],"source":"github_advisory_database","ghsa_id":"GHSA-h669-8m4g-r2hc","summary":"MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport","severity":"high","cvss_score":7.5,"ecosystems":["rubygems"],"references":["https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-h669-8m4g-r2hc","https://nvd.nist.gov/vuln/detail/CVE-2026-67432","https://github.com/modelcontextprotocol/ruby-sdk/commit/772e0cb1f9db69312006926eee59a7287ad50166","https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0","https://github.com/advisories/GHSA-h669-8m4g-r2hc"],"updated_at":"2026-07-30T14:44:08.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","published_at":"2026-07-30T14:44:06.000Z","withdrawn_at":null,"affected_packages":[{"name":"mcp","ecosystem":"rubygems","first_patched":"0.23.0","vulnerable_range":"<= 0.22.0"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:43.312Z"},{"id":"cms7nmzouaymzkh0cwotml2xx","channel":"security","topic":"github-advisories","title":"HIGH: MCP Ruby SDK: Ruby SSE Session Poisoning","summary":"high severity · mcp · CVE-2026-67431","payload":{"cve":"CVE-2026-67431","url":"https://github.com/advisories/GHSA-5p9g-j988-pcwv","cwes":["CWE-284"],"source":"github_advisory_database","ghsa_id":"GHSA-5p9g-j988-pcwv","summary":"MCP Ruby SDK: Ruby SSE Session Poisoning","severity":"high","cvss_score":null,"ecosystems":["rubygems"],"references":["https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-5p9g-j988-pcwv","https://nvd.nist.gov/vuln/detail/CVE-2026-67431","https://github.com/modelcontextprotocol/ruby-sdk/commit/35466605319a34e4c7808712ae9bb1ca1afb2356","https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0","https://github.com/advisories/GHSA-5p9g-j988-pcwv"],"updated_at":"2026-07-30T14:44:29.000Z","cvss_vector":null,"published_at":"2026-07-30T14:44:28.000Z","withdrawn_at":null,"affected_packages":[{"name":"mcp","ecosystem":"rubygems","first_patched":"0.23.0","vulnerable_range":"<= 0.22.0"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:42.607Z"},{"id":"cms7nmz4faymxkh0c7ub2q5mv","channel":"security","topic":"github-advisories","title":"MEDIUM: linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect","summary":"medium severity · linuxfabrik-lib · CVE-2026-67435","payload":{"cve":"CVE-2026-67435","url":"https://github.com/advisories/GHSA-4jc5-g844-4x33","cwes":["CWE-200","CWE-918"],"source":"github_advisory_database","ghsa_id":"GHSA-4jc5-g844-4x33","summary":"linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect","severity":"medium","cvss_score":null,"ecosystems":["pip"],"references":["https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-4jc5-g844-4x33","https://nvd.nist.gov/vuln/detail/CVE-2026-67435","https://github.com/Linuxfabrik/lib/commit/6573ff9347e541200305d278d2663d2e54e052ff","https://github.com/Linuxfabrik/lib/releases/tag/v6.0.0","https://github.com/advisories/GHSA-4jc5-g844-4x33"],"updated_at":"2026-07-30T14:46:13.000Z","cvss_vector":null,"published_at":"2026-07-30T14:46:13.000Z","withdrawn_at":null,"affected_packages":[{"name":"linuxfabrik-lib","ecosystem":"pip","first_patched":"6.0.0","vulnerable_range":"< 6.0.0"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:41.871Z"},{"id":"cms7nmykraymtkh0cvjhgl01a","channel":"security","topic":"github-advisories","title":"CRITICAL: Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)","summary":"critical severity · flyto-core · CVE-2026-67429","payload":{"cve":"CVE-2026-67429","url":"https://github.com/advisories/GHSA-2956-977x-2w3r","cwes":["CWE-22","CWE-73"],"source":"github_advisory_database","ghsa_id":"GHSA-2956-977x-2w3r","summary":"Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)","severity":"critical","cvss_score":10,"ecosystems":["pip"],"references":["https://github.com/flytohub/flyto-core/security/advisories/GHSA-2956-977x-2w3r","https://nvd.nist.gov/vuln/detail/CVE-2026-67429","https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc","https://github.com/flytohub/flyto-core/releases/tag/v2.26.6","https://github.com/advisories/GHSA-2956-977x-2w3r"],"updated_at":"2026-07-30T14:46:44.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H","published_at":"2026-07-30T14:46:43.000Z","withdrawn_at":null,"affected_packages":[{"name":"flyto-core","ecosystem":"pip","first_patched":"2.26.7","vulnerable_range":"< 2.26.7"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:41.163Z"},{"id":"cms7nmy1paymrkh0ctek6hncp","channel":"security","topic":"github-advisories","title":"HIGH: Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted","summary":"high severity · flyto-core · CVE-2026-67427","payload":{"cve":"CVE-2026-67427","url":"https://github.com/advisories/GHSA-hr7p-wg7r-hg9m","cwes":["CWE-522","CWE-668","CWE-693"],"source":"github_advisory_database","ghsa_id":"GHSA-hr7p-wg7r-hg9m","summary":"Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted","severity":"high","cvss_score":8.6,"ecosystems":["pip"],"references":["https://github.com/flytohub/flyto-core/security/advisories/GHSA-hr7p-wg7r-hg9m","https://nvd.nist.gov/vuln/detail/CVE-2026-67427","https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc","https://github.com/flytohub/flyto-core/releases/tag/v2.26.6","https://github.com/advisories/GHSA-hr7p-wg7r-hg9m"],"updated_at":"2026-07-30T14:47:03.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","published_at":"2026-07-30T14:47:01.000Z","withdrawn_at":null,"affected_packages":[{"name":"flyto-core","ecosystem":"pip","first_patched":"2.26.7","vulnerable_range":"< 2.26.7"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:40.477Z"},{"id":"cms7nmxjdaympkh0cuddm6i5q","channel":"security","topic":"github-advisories","title":"HIGH: Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url","summary":"high severity · flyto-core · CVE-2026-67425","payload":{"cve":"CVE-2026-67425","url":"https://github.com/advisories/GHSA-qq9q-xgm3-xv9g","cwes":["CWE-201","CWE-522"],"source":"github_advisory_database","ghsa_id":"GHSA-qq9q-xgm3-xv9g","summary":"Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url","severity":"high","cvss_score":8.6,"ecosystems":["pip"],"references":["https://github.com/flytohub/flyto-core/security/advisories/GHSA-qq9q-xgm3-xv9g","https://nvd.nist.gov/vuln/detail/CVE-2026-67425","https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc","https://github.com/flytohub/flyto-core/releases/tag/v2.26.6","https://github.com/advisories/GHSA-qq9q-xgm3-xv9g"],"updated_at":"2026-07-30T14:47:18.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","published_at":"2026-07-30T14:47:16.000Z","withdrawn_at":null,"affected_packages":[{"name":"flyto-core","ecosystem":"pip","first_patched":"2.26.7","vulnerable_range":"< 2.26.7"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:39.817Z"},{"id":"cms7nmx15aymnkh0c9hm1jril","channel":"security","topic":"github-advisories","title":"CRITICAL: Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration","summary":"critical severity · flyto-core · CVE-2026-67426","payload":{"cve":"CVE-2026-67426","url":"https://github.com/advisories/GHSA-jx74-cqjv-2c67","cwes":["CWE-306","CWE-522","CWE-918"],"source":"github_advisory_database","ghsa_id":"GHSA-jx74-cqjv-2c67","summary":"Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration","severity":"critical","cvss_score":9.3,"ecosystems":["pip"],"references":["https://github.com/flytohub/flyto-core/security/advisories/GHSA-jx74-cqjv-2c67","https://nvd.nist.gov/vuln/detail/CVE-2026-67426","https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9","https://github.com/flytohub/flyto-core/releases/tag/v2.26.7","https://github.com/advisories/GHSA-jx74-cqjv-2c67"],"updated_at":"2026-07-30T14:47:43.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N","published_at":"2026-07-30T14:47:41.000Z","withdrawn_at":null,"affected_packages":[{"name":"flyto-core","ecosystem":"pip","first_patched":"2.26.7","vulnerable_range":"<= 2.26.6"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:39.162Z"},{"id":"cms7nmwhjaymlkh0ccab737vn","channel":"security","topic":"github-advisories","title":"HIGH: Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)","summary":"high severity · flyto-core · CVE-2026-67428","payload":{"cve":"CVE-2026-67428","url":"https://github.com/advisories/GHSA-pgwh-4jj4-qm8v","cwes":["CWE-918"],"source":"github_advisory_database","ghsa_id":"GHSA-pgwh-4jj4-qm8v","summary":"Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)","severity":"high","cvss_score":8.5,"ecosystems":["pip"],"references":["https://github.com/flytohub/flyto-core/security/advisories/GHSA-pgwh-4jj4-qm8v","https://nvd.nist.gov/vuln/detail/CVE-2026-67428","https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9","https://github.com/flytohub/flyto-core/releases/tag/v2.26.7","https://github.com/advisories/GHSA-pgwh-4jj4-qm8v"],"updated_at":"2026-07-30T14:48:09.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","published_at":"2026-07-30T14:48:05.000Z","withdrawn_at":null,"affected_packages":[{"name":"flyto-core","ecosystem":"pip","first_patched":"2.26.7","vulnerable_range":"<= 2.26.6"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:38.456Z"},{"id":"cms7nmvqxaymhkh0c8gs2ma72","channel":"security","topic":"github-advisories","title":"HIGH: Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation","summary":"high severity · flyto-core · CVE-2026-67424","payload":{"cve":"CVE-2026-67424","url":"https://github.com/advisories/GHSA-c9hr-64h3-gxpc","cwes":["CWE-918"],"source":"github_advisory_database","ghsa_id":"GHSA-c9hr-64h3-gxpc","summary":"Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation","severity":"high","cvss_score":8.5,"ecosystems":["pip"],"references":["https://github.com/flytohub/flyto-core/security/advisories/GHSA-c9hr-64h3-gxpc","https://nvd.nist.gov/vuln/detail/CVE-2026-67424","https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9","https://github.com/flytohub/flyto-core/releases/tag/v2.26.7","https://github.com/advisories/GHSA-c9hr-64h3-gxpc"],"updated_at":"2026-07-30T14:48:19.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","published_at":"2026-07-30T14:48:16.000Z","withdrawn_at":null,"affected_packages":[{"name":"flyto-core","ecosystem":"pip","first_patched":"2.26.7","vulnerable_range":"<= 2.26.6"}]},"public_metadata":null,"published_at":"2026-07-30T15:14:37.497Z"},{"id":"cms6em8w2amldkh0crahd37di","channel":"security","topic":"github-advisories","title":"MEDIUM: OpenTelemetry Javaagent RMI context propagation allows resource exhaustion","summary":"medium severity · io.opentelemetry.javaagent:opentelemetry-javaagent · CVE-2026-54712","payload":{"cve":"CVE-2026-54712","url":"https://github.com/advisories/GHSA-fq3f-m5qm-99f5","cwes":["CWE-400"],"source":"github_advisory_database","ghsa_id":"GHSA-fq3f-m5qm-99f5","summary":"OpenTelemetry Javaagent RMI context propagation allows resource exhaustion","severity":"medium","cvss_score":5.3,"ecosystems":["maven"],"references":["https://github.com/open-telemetry/opentelemetry-java-instrumentation/security/advisories/GHSA-fq3f-m5qm-99f5","https://nvd.nist.gov/vuln/detail/CVE-2026-54712","https://github.com/open-telemetry/opentelemetry-java-instrumentation/pull/17870","https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/6ef18806d5daa4913619e4cb33d2d7ed6a853c22","https://github.com/open-telemetry/opentelemetry-java-instrumentation/releases/tag/v2.27.0"],"updated_at":"2026-07-29T17:16:33.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","published_at":"2026-07-29T17:16:32.000Z","withdrawn_at":null,"affected_packages":[{"name":"io.opentelemetry.javaagent:opentelemetry-javaagent","ecosystem":"maven","first_patched":"2.27.0","vulnerable_range":"< 2.27.0"}]},"public_metadata":null,"published_at":"2026-07-29T18:14:25.155Z"},{"id":"cms6em86haml7kh0cl1smwmbk","channel":"security","topic":"github-advisories","title":"MEDIUM: OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords","summary":"medium severity · io.opentelemetry.javaagent:opentelemetry-javaagent · CVE-2026-54704","payload":{"cve":"CVE-2026-54704","url":"https://github.com/advisories/GHSA-rwqx-fvqh-6wm4","cwes":["CWE-532"],"source":"github_advisory_database","ghsa_id":"GHSA-rwqx-fvqh-6wm4","summary":"OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords","severity":"medium","cvss_score":6.5,"ecosystems":["maven"],"references":["https://github.com/open-telemetry/opentelemetry-java-instrumentation/security/advisories/GHSA-rwqx-fvqh-6wm4","https://nvd.nist.gov/vuln/detail/CVE-2026-54704","https://github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18754","https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/7ac7fa6fda6c2e3b65bc5d3c6eba050311a49511","https://github.com/open-telemetry/opentelemetry-java-instrumentation/releases/tag/v2.28.0"],"updated_at":"2026-07-29T17:18:34.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","published_at":"2026-07-29T17:18:34.000Z","withdrawn_at":null,"affected_packages":[{"name":"io.opentelemetry.javaagent:opentelemetry-javaagent","ecosystem":"maven","first_patched":"2.28.0-alpha","vulnerable_range":"< 2.28.0-alpha"}]},"public_metadata":null,"published_at":"2026-07-29T18:14:24.233Z"},{"id":"cms6em7doaml5kh0c1o1d24me","channel":"security","topic":"github-advisories","title":"MEDIUM: mathlive's Lack of Escaping of HTML allows for XSS","summary":"medium severity · mathlive · CVE-2026-54705","payload":{"cve":"CVE-2026-54705","url":"https://github.com/advisories/GHSA-fm7p-gw32-828p","cwes":["CWE-116"],"source":"github_advisory_database","ghsa_id":"GHSA-fm7p-gw32-828p","summary":"mathlive's Lack of Escaping of HTML allows for XSS","severity":"medium","cvss_score":6.3,"ecosystems":["npm"],"references":["https://github.com/arnog/mathlive/security/advisories/GHSA-fm7p-gw32-828p","https://github.com/arnog/mathlive/issues/3028","https://github.com/arnog/mathlive/commit/5fe1c46153883f9ec0249a5c8c34e64aaae9cfb8","https://github.com/advisories/GHSA-fm7p-gw32-828p"],"updated_at":"2026-07-29T17:21:27.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","published_at":"2026-07-29T17:21:26.000Z","withdrawn_at":null,"affected_packages":[{"name":"mathlive","ecosystem":"npm","first_patched":"0.110.0","vulnerable_range":"<= 0.109.2"}]},"public_metadata":null,"published_at":"2026-07-29T18:14:23.196Z"},{"id":"cms6cgpynam25kh0c3ldy3zde","channel":"security","topic":"github-advisories","title":"HIGH: Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure","summary":"high severity · alextselegidis/easyappointments · CVE-2026-55651","payload":{"cve":"CVE-2026-55651","url":"https://github.com/advisories/GHSA-4vmm-5qvc-w5p7","cwes":["CWE-200"],"source":"github_advisory_database","ghsa_id":"GHSA-4vmm-5qvc-w5p7","summary":"Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure","severity":"high","cvss_score":7.1,"ecosystems":["composer"],"references":["https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-4vmm-5qvc-w5p7","https://nvd.nist.gov/vuln/detail/CVE-2026-55651","https://github.com/alextselegidis/easyappointments/commit/ebbe41130dafa58b0716426c56c8cfd4c22dbceb","https://github.com/alextselegidis/easyappointments/releases/tag/1.6.0","https://github.com/advisories/GHSA-4vmm-5qvc-w5p7"],"updated_at":"2026-07-29T16:22:19.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N","published_at":"2026-07-29T16:22:17.000Z","withdrawn_at":null,"affected_packages":[{"name":"alextselegidis/easyappointments","ecosystem":"composer","first_patched":null,"vulnerable_range":"= 1.5.2"}]},"public_metadata":null,"published_at":"2026-07-29T17:14:08.111Z"},{"id":"cms6cgpepam23kh0cz4c6dz04","channel":"security","topic":"github-advisories","title":"LOW: Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network","summary":"low severity · alextselegidis/easyappointments · CVE-2026-52840","payload":{"cve":"CVE-2026-52840","url":"https://github.com/advisories/GHSA-pm5p-7w5h-jm5q","cwes":["CWE-918"],"source":"github_advisory_database","ghsa_id":"GHSA-pm5p-7w5h-jm5q","summary":"Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network","severity":"low","cvss_score":2.7,"ecosystems":["composer"],"references":["https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-pm5p-7w5h-jm5q","https://nvd.nist.gov/vuln/detail/CVE-2026-52840","https://github.com/alextselegidis/easyappointments/commit/2da2baed18ec32ad7916e507815709c8f010d510","https://github.com/alextselegidis/easyappointments/commit/4abb10545d83ac1a57d03f6502376ee67696ea7c","https://github.com/alextselegidis/easyappointments/commit/6b34b78c47790dfd1dec27cf62926db51be276e9"],"updated_at":"2026-07-29T16:24:30.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","published_at":"2026-07-29T16:24:27.000Z","withdrawn_at":null,"affected_packages":[{"name":"alextselegidis/easyappointments","ecosystem":"composer","first_patched":null,"vulnerable_range":"<= 1.5.2"}]},"public_metadata":null,"published_at":"2026-07-29T17:14:07.393Z"},{"id":"cms6cgoucam21kh0cnlfsl4uc","channel":"security","topic":"github-advisories","title":"LOW: Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass","summary":"low severity · alextselegidis/easyappointments · CVE-2026-52839","payload":{"cve":"CVE-2026-52839","url":"https://github.com/advisories/GHSA-w8xc-8g92-v77h","cwes":["CWE-639","CWE-862"],"source":"github_advisory_database","ghsa_id":"GHSA-w8xc-8g92-v77h","summary":"Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass","severity":"low","cvss_score":3.3,"ecosystems":["composer"],"references":["https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-w8xc-8g92-v77h","https://nvd.nist.gov/vuln/detail/CVE-2026-52839","https://github.com/alextselegidis/easyappointments/commit/725eafa647308846ce887657db12771a829e42ef","https://github.com/alextselegidis/easyappointments/releases/tag/1.6.0","https://github.com/advisories/GHSA-w8xc-8g92-v77h"],"updated_at":"2026-07-29T16:26:27.000Z","cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N","published_at":"2026-07-29T16:26:25.000Z","withdrawn_at":null,"affected_packages":[{"name":"alextselegidis/easyappointments","ecosystem":"composer","first_patched":"1.6.0","vulnerable_range":"<= 1.5.2"}]},"public_metadata":null,"published_at":"2026-07-29T17:14:06.660Z"}]