CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad

CVEReports
•11 minutes ago•CVE-2026-105850
8.8

CVE-2026-105850: Race Condition and Order Double-Processing in @payloadcms/plugin-ecommerce

A high-severity race condition vulnerability exists in @payloadcms/plugin-ecommerce within the Stripe payment adapter's order confirmation pipeline. Unauthenticated attackers or parallel webhook deliveries can exploit sequential, non-atomic database operations to bypass state verifications, leading to duplicate order creation, multiple inventory decrements, and inconsistent database records.

Amit Schendel
Amit Schendel
2 views•7 min read
•about 1 hour ago•CVE-2026-105849
7.7

CVE-2026-105849: Sensitive Data Exposure and Privilege Escalation in Payload CMS API Key Authentication

A sensitive data exposure vulnerability in Payload CMS allows authenticated low-privilege users to retrieve decrypted, plaintext API keys of other users, including administrators, leading to full administrative account takeover and privilege escalation.

Amit Schendel
Amit Schendel
4 views•5 min read
•about 2 hours ago•CVE-2026-86540
8.5

CVE-2026-86540: Arbitrary Code Execution via LSP Binary Override in knowns

CVE-2026-86540 is a high-severity arbitrary code execution vulnerability in knowns, a repository management tool. The vulnerability occurs when the application parses and executes unvalidated language server binary overrides defined within a project's local configuration file.

Amit Schendel
Amit Schendel
6 views•5 min read
•about 3 hours ago•CVE-2026-105854
8.7

CVE-2026-105854: Regular Expression Denial of Service (ReDoS) and Uncontrolled Resource Consumption in Payload CMS

Payload CMS, a popular open-source headless Content Management System, contains a critical Regular Expression Denial of Service (ReDoS) and uncontrolled resource consumption vulnerability in versions prior to 3.90.0 and canary versions prior to 4.0.0-canary.34. Due to nested quantifiers in the multipart boundary regex validation pattern, and the absence of streaming backpressure controls, remote attackers can trigger catastrophic backtracking and memory exhaustion. This blocks the single-threaded Node.js event loop, resulting in a persistent and complete Denial of Service (DoS).

Amit Schendel
Amit Schendel
5 views•6 min read
•about 4 hours ago•CVE-2026-105855
7.6

CVE-2026-105855: Privilege Escalation via Improper Access Control on Password Fields in Payload CMS

An Improper Access Control vulnerability (CWE-284) in Payload CMS prior to version 3.90.0 and 4.0.0-canary.34 allows authenticated, low-privileged users to bypass field-level access control restrictions and overwrite the password of other accounts, leading to complete account takeover and privilege escalation.

Alon Barad
Alon Barad
9 views•6 min read
•about 5 hours ago•CVE-2026-105804
5.7

CVE-2026-105804: Insecure Default PBKDF2 Password Hashing Configuration in Payload CMS

Payload CMS was discovered to use an insecure default configuration for its password-hashing mechanism. The system requested a 512-byte key from PBKDF2-HMAC-SHA256 with 25,000 iterations, creating a severe cryptographic asymmetry. While the defending server sequentially computed 16 blocks of key material (equivalent to 400,000 internal iterations), an offline attacker only needed to compute the first 32-byte block to verify password guesses. This allowed offline attackers to crack stolen database hashes 16 times faster than intended by the security design.

Alon Barad
Alon Barad
6 views•6 min read
•about 6 hours ago•GHSA-WQ5F-XC86-PV6W
7.8

CVE-2026-96889: Remote Code Execution via Use-After-Free in librsvg (VectorFreed)

VectorFreed identifies a critical Use-After-Free (UAF) memory corruption vulnerability in librsvg (CVE-2026-96889), which manifests when parsing structured SVG documents containing nested XML inclusions (XIncludes) and duplicate entity declarations. The flaw results from an entity ownership conflict where librsvg prematurely deallocates an xmlEntity structure still actively referenced by the underlying libxml2 parser context. When transitively compiled into downstream applications such as the high-performance sharp image processing library, this vulnerability facilitates denial of service and unauthenticated remote code execution on the host operating system.

Amit Schendel
Amit Schendel
6 views•8 min read
•about 8 hours ago•CVE-2026-102275
6.5

CVE-2026-102275: Public/Private Key Identity Confusion in PyJWT OKP JWK Processing

CVE-2026-102275 (GHSA-x33g-cr3x-6449) is a public/private key identity confusion vulnerability in PyJWT versions 2.1.0 through 2.14.0. When importing Octet Key Pair (OKP) JSON Web Keys (JWKs) representing Ed25519 or Ed448 curves, PyJWT fails to verify that the public parameter 'x' matches the private parameter 'd'. An attacker can construct a hybrid JWK combining a victim's public key with the attacker's private key. In protocols like DPoP that bind sessions via public key thumbprints, this allows the attacker to authenticate as the victim while signing proofs with their own private key, fully bypassing sender-constrained security guarantees.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 9 hours ago•CVE-2026-104181
5.4

CVE-2026-104181: Authentication Bypass and Privilege Escalation in Filament Multi-Factor Authentication

An authentication bypass and privilege escalation vulnerability exists in Filament (filamentphp/filament) due to missing password verification during multi-factor authentication (MFA) setup and management. An attacker with access to an active session can modify or disable MFA, leading to account hijacking.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 10 hours ago•CVE-2026-102600
7.5

CVE-2026-102600: Unhandled Runtime Exception via Unsafe Prototype Lookup in @socket.io/cluster-engine

A critical Denial of Service (DoS) vulnerability exists in @socket.io/cluster-engine before version 0.1.1. Unauthenticated remote attackers can crash the server process by supplying inherited prototype property names as session identifiers.

Alon Barad
Alon Barad
9 views•6 min read
•about 11 hours ago•CVE-2026-96747
5.0

CVE-2026-96747: Local Unix Domain Socket SSRF via KMS Endpoint Manipulation in PyMongo

A vulnerability in the Client-Side Field-Level Encryption (CSFLE) component of the MongoDB Python Driver (PyMongo) allows an attacker with database write access to trigger local Unix domain socket connections. By manipulating the Key Management Service (KMS) endpoint configuration inside the key vault collection to end with a '.sock' extension, an attacker forces the application to perform a Server-Side Request Forgery (SSRF) against internal Unix domain sockets.

Alon Barad
Alon Barad
8 views•6 min read
•about 12 hours ago•CVE-2026-52993
9.8

CVE-2026-52993: Double-Free Vulnerability in Linux Kernel TIPC Module

A critical double-free vulnerability exists in the Transparent Inter-Process Communication (TIPC) module of the Linux kernel, specifically within the fragment reassembly implementation in `tipc_buf_append()`. This vulnerability can be triggered locally or remotely to cause kernel heap corruption, leading to local privilege escalation or denial of service.

Amit Schendel
Amit Schendel
9 views•7 min read
SeverityExploitPeriodCatalog
Sort

Or generate a custom report

Search for a CVE ID (e.g. CVE-2024-1234) to generate an AI-powered vulnerability analysis

Automated vulnerability intelligence. 3,097+ reports.