Where
AND
-Infinity
0

npm/jsdiffjsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Risk 31
Severity
2.7
EPSS
0.02%
First published (updated )

pip/aiohttpAIOHTTP Vulnerable to Cookie Parser Warning Storm

Risk 29
Severity
2.7
First published (updated )

pypi/aiohttpAIOHTTP Regex Mismatch Allows Unicode in ASCII-Only Protocol Fields

Risk 29
Severity
2.7
First published (updated )

npm/viteVite's `server.fs` settings were not applied to HTML files

Risk 27
Severity
2.3
First published (updated )

npm/viteVite middleware may serve files starting with the same name with the public directory

Risk 27
Severity
2.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/aiohttpAIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections

Risk 43
Severity
1.7
First published (updated )

npm/brace-expansionjuliangruber brace-expansion index.js expand redos

Risk 13
Severity
2.3
EPSS
0.06%
First published (updated )

go/github.com/redis/go-redis/v9go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment

Risk 15
Severity
3.7
EPSS
0.06%
First published (updated )

go/github.com/golang-jwt/jwt/v4Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt

Risk 18
Severity
3.1
First published (updated )

linuxfoundation Runcrunc can be confused to create empty files/directories on the host

Risk 21
Severity
3.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/go.temporal.io/serverInsecure Default Authorization in Temporal Server

Risk 25
Severity
3.6
First published (updated )

redhat/go-toolsetSession tickets lack random ticket_age_add in crypto/tls

Risk 18
Severity
3.1
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203