| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-59901 🧪 | Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang | netty | netty | High | 8.7 | 2026-07-29 17:48:40 | Deep Dive |
| CVE-2026-18236 🧪 | Google-ADK Continuation Forgery | Google-ADK | Critical | 9.3 | 2026-07-29 17:37:02 | Deep Dive | |
| CVE-2026-54680 🧪 | Logging operator has Fluentd configuration injection that allows remote code execution | kube-logging | logging-operator | Critical | 9.9 | 2026-07-29 16:57:17 | Deep Dive |
| CVE-2026-54693 🧪 | ZITADEL Users Can Self-Verify Email/Phone via API | zitadel | zitadel | High | 8.2 | 2026-07-29 16:50:40 | Deep Dive |
| CVE-2026-64560 🧪 | posix-cpu-timers: Prevent UAF caused by non-leader exec() race | Linux | Linux | High | 7.8 | 2026-07-29 16:47:18 | Deep Dive |
| CVE-2026-54727 🧪 | proot-distro has a Container Isolation Bypass via Crafted Restore Archive | termux | proot-distro | High | 8.2 | 2026-07-29 16:41:47 | Deep Dive |
| CVE-2026-13697 🧪 | undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives | undici | undici | High | 7.4 | 2026-07-29 16:32:40 | Deep Dive |
| CVE-2026-54574 🧪 | `proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive | termux | proot-distro | High | 8.2 | 2026-07-29 16:32:16 | Deep Dive |
| CVE-2026-15144 🧪 | @fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotation | @fastify/rate-limit | @fastify/rate-limit | High | 7.3 | 2026-07-29 16:10:25 | Deep Dive |
| CVE-2026-54735 🧪 | prebid-server's request forgery vulnerability allows for possible host environment data extraction | prebid | prebid-server | Critical | 10.0 | 2026-07-29 15:59:47 | Deep Dive |
| CVE-2026-60113 🧪 | AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes | NASA-AMMOS | AIT-DSN | Critical | 9.8 | 2026-07-29 15:40:27 | Deep Dive |
| CVE-2026-60112 🧪 | AIT-GUI < 2.5.1 Missing Authentication via Sessions.create() | NASA-AMMOS | AIT-GUI | Critical | 9.8 | 2026-07-29 15:35:45 | Deep Dive |
| CVE-2026-16543 🧪 | Kong Operator cluster-wide ingress configuration DoS via embedded KIC CA-certificate ID collision | - | - | High | 7.1 | 2026-07-29 15:29:03 | Deep Dive |
| CVE-2026-15228 🧪 | Kong Kubernetes Ingress Controller cluster-wide ingress configuration DoS via CA-certificate ID collision | - | - | High | 7.1 | 2026-07-29 15:28:30 | Deep Dive |
| CVE-2026-54078 🧪 | veraPDF Validation XXE via Rich Text | veraPDF | veraPDF-validation | High | 8.7 | 2026-07-29 15:11:05 | Deep Dive |
| CVE-2026-54079 🧪 | veraPDF Validation XXE via XFA | veraPDF | veraPDF-validation | High | 8.7 | 2026-07-29 15:07:24 | Deep Dive |
| CVE-2026-54666 🧪 | swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies | acacode | swagger-typescript-api | High | 8.3 | 2026-07-29 14:34:49 | Deep Dive |
| CVE-2026-54664 🧪 | swagger-typescript-api vulnerable to code injection via unescaped enum string values | acacode | swagger-typescript-api | High | 8.3 | 2026-07-29 14:32:41 | Deep Dive |
| CVE-2026-54661 🧪 | swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template | acacode | swagger-typescript-api | High | 8.3 | 2026-07-29 14:30:30 | Deep Dive |
| CVE-2026-54662 🧪 | swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template | acacode | swagger-typescript-api | High | 8.3 | 2026-07-29 14:26:16 | Deep Dive |