Where
AND
-Infinity
0

pip/pillowPillow is vulnerable to a FITS GZIP decompression bomb

Risk 47
Severity
8.7
First published (updated )

Apache TomcatApache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor

Risk 46
Severity
7.5
First published (updated )

Apache TomcatApache Tomcat: TLS cipher order is not preserved

Risk 46
Severity
7.5
First published (updated )

npm/serialize-javascriptSerialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects

Risk 43
Severity
7.5
First published (updated )

npm/node-forgeForge has signature forgery in Ed25519 due to missing S > L check

Risk 31
Severity
7.5
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/node-forgeForge has signature forgery in RSA-PKCS due to ASN.1 extra field

Risk 31
Severity
7.5
EPSS
0.03%
First published (updated )

npm/node-forgeForge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )

npm/path-to-regexppath-to-regexp vulnerable to Denial of Service via sequential optional groups

Risk 31
Severity
7.5
EPSS
0.05%
First published (updated )

npm/brace-expansionbrace-expansion: Zero-step sequence causes process hang and memory exhaustion

Risk 43
Severity
7.5
First published (updated )

npm/path-to-regexppath-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters

Risk 31
Severity
7.5
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/picomatchPicomatch has a ReDoS vulnerability via extglob quantifiers

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )

IBM WebSphere Application ServerIBM WebSphere Application Server Liberty is affected by a privilege escalation vulnerability

Risk 66
Severity
7.2
First published (updated )

npm/flattedflatted: Prototype Pollution via parse()

Risk 61
Severity
8.9
EPSS
0.03%
First published (updated )

pip/nltkNLTK has unauthenticated remote shutdown in nltk.app.wordnet_app

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )

npm/socket.io-parsersocket.io allows an unbounded number of binary attachments

Risk 33
Severity
8.7
EPSS
0.08%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

NaturalIntelligence fast-xml-parserfast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )

npm/undiciundici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid server_max_window_bits Validation

Risk 43
Severity
7.5
First published (updated )

npm/undiciundici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and crashes the client

Risk 43
Severity
7.5
First published (updated )

npm/undiciundici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-deflate Decompression

Risk 43
Severity
7.5
First published (updated )

npm/flattedflatted: Unbounded recursion DoS in parse() revive phase

Risk 31
Severity
7.5
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/node-tarnode-tar Symlink Path Traversal via Drive-Relative Linkpath

Risk 31
Severity
8.2
EPSS
0.01%
First published (updated )

npm/immutableImmutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable

Risk 61
Severity
8.7
EPSS
0.06%
First published (updated )

pypi/nltkPath Traversal in nltk/nltk

Risk 64
Severity
7.5
First published (updated )

npm/minimatchminimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Risk 31
Severity
7.5
EPSS
0.05%
First published (updated )

npm/minimatchminimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Risk 31
Severity
7.5
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

nltk/nltkZip Slip Vulnerability in nltk/nltk Leading to Remote Code Execution

Risk 87
Severity
8.8
First published (updated )

npm/tarnode-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction

Risk 38
Severity
7.1
EPSS
0.01%
First published (updated )

Apache AvroApache Avro Java SDK: Code injection on Java generated code

Risk 55
Severity
7.3
First published (updated )

pip/pillowPillow has an out-of-bounds write when loading PSD images

Risk 61
Severity
8.9
EPSS
0.02%
First published (updated )

IBM WebSphere Application Server LibertyIBM WebSphere Application Server Liberty Path Traversal

Risk 60
Severity
7.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203