Forem

# cve

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
CVE-2026-23954: Incus Escape: From Templates to Host Root

CVE-2026-23954: Incus Escape: From Templates to Host Root

Comments
2 min read
CVE-2025-22234: The 73rd Byte: How a Spring Security Fix Created a Timing Leak

CVE-2025-22234: The 73rd Byte: How a Spring Security Fix Created a Timing Leak

Comments
2 min read
GHSA-JP3Q-WWP3-PWV9: Freeform, Free Execution: Stored XSS in Craft CMS's Favorite Form Builder

GHSA-JP3Q-WWP3-PWV9: Freeform, Free Execution: Stored XSS in Craft CMS's Favorite Form Builder

Comments
2 min read
CVE-2025-5419 - Google Chrome V8 Engine Out-of-Bounds Read/Write Vulnerability
Cover image for CVE-2025-5419 - Google Chrome V8 Engine Out-of-Bounds Read/Write Vulnerability

CVE-2025-5419 - Google Chrome V8 Engine Out-of-Bounds Read/Write Vulnerability

Comments
9 min read
GHSA-F456-RF33-4626: Mocking the Mock: RCE via Orval Code Generation

GHSA-F456-RF33-4626: Mocking the Mock: RCE via Orval Code Generation

Comments
2 min read
CVE-2026-24061: Telnet Strikes Back: GNU Inetutils Root Authentication Bypass

CVE-2026-24061: Telnet Strikes Back: GNU Inetutils Root Authentication Bypass

Comments
2 min read
GHSA-RJR4-V43M-PXQ6: The Lie in the Sponge: Breaking Triton VM's STARKs

GHSA-RJR4-V43M-PXQ6: The Lie in the Sponge: Breaking Triton VM's STARKs

Comments
2 min read
CVE-2026-24001: Diffing Dangerously: Infinite Loops and ReDoS in jsdiff

CVE-2026-24001: Diffing Dangerously: Infinite Loops and ReDoS in jsdiff

Comments
2 min read
CVE-2025-13465: Lodash: The Delete Button for the Universe (CVE-2025-13465)

CVE-2025-13465: Lodash: The Delete Button for the Universe (CVE-2025-13465)

Comments
2 min read
CVE-2026-24047: Backstage Pass: Breaking Out of the Sandbox with Symlinks

CVE-2026-24047: Backstage Pass: Breaking Out of the Sandbox with Symlinks

Comments
2 min read
CVE-2026-23733: Mermaid's Song: From Flowchart to Remote Code Execution in LobeChat

CVE-2026-23733: Mermaid's Song: From Flowchart to Remote Code Execution in LobeChat

Comments
2 min read
GHSA-PCHF-49FH-W34R: Soft Serve, Hard Fail: The Context Pollution Authentication Bypass

GHSA-PCHF-49FH-W34R: Soft Serve, Hard Fail: The Context Pollution Authentication Bypass

Comments
2 min read
CVE-2026-21852: Premature Exfiltration: How Claude Code Leaked Your Keys Before Asking for Permission

CVE-2026-21852: Premature Exfiltration: How Claude Code Leaked Your Keys Before Asking for Permission

Comments
2 min read
CVE-2026-23957: Death by Allocation: Crashing Seroval with a Single Byte

CVE-2026-23957: Death by Allocation: Crashing Seroval with a Single Byte

Comments
2 min read
CVE-2026-23886: CVE-2026-23886: The Case of the Fatal Uppercase

CVE-2026-23886: CVE-2026-23886: The Case of the Fatal Uppercase

Comments
2 min read
CVE-2026-23947: Comment Injection to RCE: Breaking Orval with JSDoc

CVE-2026-23947: Comment Injection to RCE: Breaking Orval with JSDoc

Comments
2 min read
CVE-2025-68613: n8n RCE: When 'this' Becomes Your Worst Nightmare

CVE-2025-68613: n8n RCE: When 'this' Becomes Your Worst Nightmare

Comments
2 min read
CVE-2026-23950: Scharfes S, Sharp Claws: Breaking Node-Tar with Unicode Ligatures

CVE-2026-23950: Scharfes S, Sharp Claws: Breaking Node-Tar with Unicode Ligatures

Comments
2 min read
CVE-2026-0831 - Arbitrary File Write Vulnerability in WordPress Templately Plugin
Cover image for CVE-2026-0831 - Arbitrary File Write Vulnerability in WordPress Templately Plugin

CVE-2026-0831 - Arbitrary File Write Vulnerability in WordPress Templately Plugin

Comments
12 min read
CVE-2025-66803: The Undead Session: Explaining the Race Condition in Hotwired Turbo

CVE-2025-66803: The Undead Session: Explaining the Race Condition in Hotwired Turbo

Comments
2 min read
CVE-2026-23829: Mailpit Stop: SMTP Header Injection via Regex Failure

CVE-2026-23829: Mailpit Stop: SMTP Header Injection via Regex Failure

Comments
2 min read
CVE-2026-0594 - Reflected Cross-Site Scripting (XSS) in WordPress
Cover image for CVE-2026-0594 - Reflected Cross-Site Scripting (XSS) in WordPress

CVE-2026-0594 - Reflected Cross-Site Scripting (XSS) in WordPress

5
Comments
10 min read
CVE-2026-23518: Fleet Fiasco: The Unverified JWT That Opened the Gates

CVE-2026-23518: Fleet Fiasco: The Unverified JWT That Opened the Gates

Comments
2 min read
CVE-2026-0712 - Grafana Open Redirect Leading to Cross-Site Scripting (XSS) Vulnerability
Cover image for CVE-2026-0712 - Grafana Open Redirect Leading to Cross-Site Scripting (XSS) Vulnerability

CVE-2026-0712 - Grafana Open Redirect Leading to Cross-Site Scripting (XSS) Vulnerability

5
Comments
9 min read
CVE-2026-0863: Snake in the Sandbox: Breaking n8n with Python 3.10 Internals

CVE-2026-0863: Snake in the Sandbox: Breaking n8n with Python 3.10 Internals

Comments
2 min read
loading...