CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad

CVEReports
•17 minutes ago•CVE-2026-91776
7.5

CVE-2026-91776: Denial of Service via Unbounded Polymorphic Cache in jackson-databind

CVE-2026-91776 is a high-severity Denial of Service (DoS) vulnerability in the FasterXML jackson-databind library. The vulnerability is caused by uncontrolled resource consumption (CWE-400) where raw, unrecognized polymorphic type IDs are cached indefinitely without boundaries inside TypeDeserializerBase. When name-based polymorphic deserialization is configured with a fallback mechanism (such as a default implementation or custom problem handlers), remote attackers can send crafted payloads containing unique unknown type IDs, causing heap exhaustion, Garbage Collection (GC) overhead limit exhaustion, and an Out-of-Memory (OOM) crash.

Alon Barad
Alon Barad
1 views•6 min read
•about 1 hour ago•CVE-2026-91777
7.5

CVE-2026-91777: Algorithmic Complexity Denial of Service in FasterXML jackson-databind

An uncontrolled resource consumption vulnerability in FasterXML jackson-databind allows remote unauthenticated attackers to cause a Denial of Service (DoS) via crafted JSON payloads containing out-of-order forward references in identity-enabled collections or maps.

Alon Barad
Alon Barad
7 views•6 min read
•about 2 hours ago•GHSA-97JJ-33GV-5XF9
6.1

GHSA-97jj-33gv-5xf9: Stored Cross-Site Scripting Bypass in league/commonmark DisallowedRawHtml Extension

A security vulnerability in league/commonmark versions 1.3.0 through 2.10.1 allows remote attackers to bypass Stored Cross-Site Scripting (XSS) protections in the DisallowedRawHtml extension. Due to an validation logic flaw in the regular expression parser, specifically handling bare, unclosed HTML blocks ending at the string boundary, raw HTML tags can be passed to the rendered output. When combined with browser-side parsing heuristics, an attacker can execute arbitrary JavaScript in the context of the user session.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 3 hours ago•GHSA-P98J-92PF-MC4P
8.1

GHSA-P98J-92PF-MC4P: DOM-Based Cross-Site Scripting (DOM XSS) via Hook Detach Bypass in DOMPurify In-Place Sanitization

A DOM-based Cross-Site Scripting (DOM XSS) vulnerability in DOMPurify allows attackers to bypass sanitization when using the in-place sanitization configuration (IN_PLACE: true) combined with custom hooks. If custom hooks detach elements during post-processing phases, nested malicious payloads can escape sterilization and execute in the browser's context.

Amit Schendel
Amit Schendel
6 views•8 min read
•about 4 hours ago•CVE-2026-97711
2.3

CVE-2026-97711: Cross-Site Scripting (XSS) via Unescaped Script-Closing Tags in serialize-javascript

A security vulnerability in serialize-javascript v7.1.1 allows Cross-Site Scripting (XSS) due to an overly greedy regular expression (SCRIPT_CLOSE_REGEXP) used during function serialization. Two secondary defects involving a spoofed toString() validation bypass and a stateful native code validator are also addressed in the fixed version v7.1.2.

Alon Barad
Alon Barad
0 views•7 min read
•about 5 hours ago•CVE-2026-101918
5.3

CVE-2026-101918: Unauthenticated Denial of Service via Recursion Exhaustion in PyJWT

A Denial of Service (DoS) vulnerability exists in the PyJWT library when parsing unverified token payloads containing deeply nested JSON structures. Because PyJWT fails to catch RecursionError during payload parsing, an unauthenticated remote attacker can crash the application thread or worker by sending a specially crafted token.

Alon Barad
Alon Barad
8 views•5 min read
•about 6 hours ago•GHSA-VCVR-R3JV-PC5J
9.8

CVE-2026-94545: SVG-Serialization Markup Injection in Vercel Satori and Next.js ImageResponse

An improper output encoding and escaping vulnerability (CWE-116) in Vercel Satori allows unauthenticated remote attackers to perform markup injection in dynamic Open Graph images generated via Next.js's ImageResponse. Unsanitized parameter interpolation into SVG elements breaks XML structural boundaries. This exposes downstream parsing, rasterization, and rendering pipelines to Server-Side Request Forgery (SSRF), Local File Read, and Remote Code Execution (RCE).

Alon Barad
Alon Barad
9 views•7 min read
•about 7 hours ago•CVE-2026-102265
5.3

CVE-2026-102265: Unhandled RecursionError in PyJWT JSON Parser Leading to Denial of Service

An uncontrolled recursion vulnerability exists in PyJWT from version 2.13.0 to 2.14.0. The vulnerability allows remote, unauthenticated attackers to cause a Denial of Service (DoS) via crafted JWT headers that trigger stack exhaustion during JSON decoding.

Amit Schendel
Amit Schendel
8 views•5 min read
•about 8 hours ago•CVE-2026-102266
7.4

CVE-2026-102266: Signature Verification Bypass in PyJWT via Empty JWK

A signature verification bypass vulnerability in PyJWT allows unauthenticated remote attackers to forge JSON Web Tokens when processing JSON Web Key Sets containing an empty symmetric key.

Alon Barad
Alon Barad
7 views•8 min read
•about 9 hours ago•GHSA-V53P-9FQP-M79J
7.5

GHSA-V53P-9FQP-M79J: Regular Expression Denial of Service (ReDoS) in Nodemailer addressparser

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Nodemailer's addressparser fallback engine before version 10.0.6. Under specific malformed inputs with excessive word boundaries, the parser exhibits quadratic backtracking, leading to high CPU utilization and event loop blockage.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 10 hours ago•GHSA-G57G-F23G-4646
6.5

GHSA-G57G-F23G-4646: Parser Differential and SMTP Injection in Nodemailer Address Parser

Nodemailer versions prior to 10.0.9 are vulnerable to a parser differential bug. When processing a quoted local-part followed by an RFC 5322 comment and trailing characters, the internal addressparser module fails to order its normalization routine correctly. This error results in the generation of malformed envelope recipient addresses containing injected whitespace and secondary domains, allowing attackers to bypass routing restrictions and exfiltrate sensitive emails.

Alon Barad
Alon Barad
5 views•7 min read
•about 11 hours ago•CVE-2026-102276
7.5

CVE-2026-102276: Denial of Service via Uncontrolled Recursion and Argument-List Exhaustion in brace-expansion

CVE-2026-102276 is a high-severity Denial of Service (DoS) vulnerability impacting the 'brace-expansion' library, a popular Node.js utility designed to expand brace patterns into combinatorial lists. Due to uncontrolled recursion and argument-list stack exhaustion within the internal parseCommaParts function, remote attackers can trigger an unhandled RangeError that abruptly terminates the Node.js process.

Alon Barad
Alon Barad
13 views•7 min read
SeverityExploitPeriodCatalog
Sort

Or generate a custom report

Search for a CVE ID (e.g. CVE-2024-1234) to generate an AI-powered vulnerability analysis

Automated vulnerability intelligence. 3,007+ reports.