Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 36627+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 5.9
CVE-2026-15712: Heap Buffer Overflow in libsoup HTTP/2 GOAWAY Frame Parsing
bugzilla.redhat.com · 2026-07-15

### Vulnerability Overview - **CVE ID**: CVE-2026-15712 - **Description**: A heap buffer overflow can be triggered in the HTTP/2 protocol parsing logic of libsoup when processing malicious network fra…

Read more
Symfony Runtime CVE-2024-50340 Patch Bypass via parse_str/argv Mismatch
github.com · 2026-07-15

### Vulnerability Overview Symfony Runtime CVE-2024-50340 Patch Bypass: Web requests can still set `APP_ENV`/`APP_DEBUG` via `parse_str`/SAPI Argv mismatch. ### Affected Versions - **Affected Versions…

Read more
Symfony Runtime CVE-2024-50348 Patch Analysis: CLI argv Bypass via QUERY_STRING
github.com · 2026-07-15

### Vulnerability Overview This vulnerability affects the `Runtime` component in the Symfony framework, specifically identified as `CVE-2024-50348`. The flaw allows attackers to bypass `argv` paramete…

Read more
TP-Link Deco M5 V1 Firmware Release Notes: Bug Fixes and Stability Patches
www.tp-link.com · 2026-07-15

### Vulnerability Overview The firmware for TP-Link Deco M5 V1 contains multiple vulnerabilities, including: 1. **False positives caused by security protection features**: In certain scenarios, the se…

Read more
TP-Link Deco M5 Weak Password Hashing Vulnerability Advisory (CVE-2026-5040)
www.tp-link.com · 2026-07-15

### Vulnerability Overview - **Vulnerability Name**: Weak Password Hashing Mechanism in TP-Link Deco M5 - **CVE Number**: CVE-2026-5040 - **CVSS Score**: 7.1 / High - **Description**: This vulnerabili…

Read more
Premium intel
CVSS 8.7
Zephyr OS recvmsg() out-of-bounds write vulnerability analysis and fix
github.com · 2026-07-15

### Vulnerability Overview The `recvmsg()` implementation for IP sockets in Zephyr (`insert_pktinfo()` in `subsys/net/lib/sockets/sockets_inet.c`) validates the user-provided ancillary data (`msg_cont…

Read more
CVSS 4.9
Linux ext2 Directory Entry Validation Vulnerability (OOB Read/Infinite Loop)
github.com · 2026-07-15

### Vulnerability Overview This vulnerability involves a validation issue in the `fs: ext2` filesystem directory entry structure during traversal. Specifically, the `ext2_fetch_dirent()` function trus…

Read more
Symfony json-path ReDoS Vulnerability (CVE-2025-45756)
github.com · 2026-07-15

# JsonPath evaluation of attacker-controlled regular expressions leads to Denial of Service (ReDoS) ## Vulnerability Overview The `match()` and `search()` filter functions in the JsonPath component pa…

Read more
Symfony JsonPath ReDoS Vulnerability Analysis and Fix
github.com · 2026-07-15

### Vulnerability Overview This vulnerability affects the `JsonCrawler` component in the Symfony framework, where regex backtracking in the `match`/`search` functions can lead to Regular Expression De…

Read more
Symfony CAS Module Host Header Injection Fix
github.com · 2026-07-15

### Vulnerability Overview This vulnerability involves an issue where trusted hosts are not configured during CAS authentication. Attackers can exploit this by constructing malicious requests to perfo…

Read more
Symfony Mime Address Class Control Character Injection Fix
github.com · 2026-07-15

### Vulnerability Overview This vulnerability affects the `Address` class in the Symfony framework, specifically regarding the improper validation and control of control characters when processing ema…

Read more
Symfony Mime CRLF Injection Vulnerability (CVE-2025-4087) Advisory
github.com · 2026-07-15

### Vulnerability Overview - **Vulnerability Name**: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address - **CVE ID**: CVE-2025-4087 - **Severity**: Moderate - **Descripti…

Read more
Symfony v7.4.12 Security Advisory: Multiple CVEs in Components
github.com · 2026-07-15

### Vulnerability Overview Symfony v7.4.12 fixes multiple security vulnerabilities affecting various components, including Notifier, HttpKernel, Mailer, HtmlSanitizer, Yaml, DomCrawler, Routing, Mime,…

Read more
Symfony v8.0.12 Security Bulletin: Multiple CVEs (XSS, XXE, RBAC Bypass)
github.com · 2026-07-15

### Vulnerability Overview The webpage screenshot displays the release notes for Symfony v8.0.12, which contains multiple security-related fixes and improvements. The main vulnerabilities addressed in…

Read more
CVE-2024-5077: Unauthenticated PHP Object Deserialization in Symfony MonologBridge
github.com · 2026-07-15

### Vulnerability Overview - **Vulnerability Name**: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener - **Vulnerability Description**: `Symfony\Bridge\Monolog\Command\Se…

Read more
Symfony HTMLSanitizer allowLinkHosts Host Bypass via URL Parser and Area Tag
github.com · 2026-07-15

### Vulnerability Overview This vulnerability affects the HTMLSanitizer component within the Symfony framework, specifically involving bypasses of `allowLinkHosts` and `allowMediaHosts`. Attackers can…

Read more
Symfony UrlGenerator Route-Requirement Bypass Leading to URL Injection (CVE-2024-45085)
github.com · 2026-07-15

### Vulnerability Overview **Title**: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection **Description**: Symfony routes can declare requirements fo…

Read more
Symfony HtmlSanitizer AllowList Bypass via URL Parsing and <area> Tag (CVE-2024-4266)
github.com · 2026-07-15

### Vulnerability Overview The `allowLinkHosts()` and `allowMediaHosts()` methods in Symfony's `HtmlSanitizer` component are vulnerable to bypass attacks. Attackers can exploit URL parsing discrepanci…

Read more
Symfony v5.4.52 Security Advisory: Fixes for XXE, Catastrophic Backtracking, and Other Vulnerabilities
github.com · 2026-07-15

### Vulnerability Overview The attached webpage screenshot displays the release notes for Symfony v5.4.52, which include fixes for multiple security vulnerabilities. Below is a summary of the key vuln…

Read more
Symfony v6.4.40 Multiple Component Security Vulnerabilities Advisory
github.com · 2026-07-15

### Vulnerability Overview Multiple security vulnerabilities have been identified in Symfony version 6.4.40, affecting various components. These vulnerabilities include runtime issues, HTML sanitizati…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.