Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.9Apache

Medium [CVE-2026-66756] Improper Protection of Alternate Path vulnerability in Apache Tika

Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.

CVE-2026-66756
Tika
Jul 30, 2026
Medium5.9Apache Updated

Medium [CVE-2026-66755] Apache Tika: Arbitrary Local File Read in ISArchiveParser

Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output, via a "Study Assay File Name" value in the ISA-Tab investigation file that traverses outside the dataset directory. Users are recommended to upgrade to version 3.3.2 or 4.0.0-beta-1, which fixes this issue.

CVE-2026-66755
Tika
Jul 30, 2026
Medium5.3Red Hat

Medium [CVE-2026-59881] Denial of Service via unnegotiated WebSocket compression

Denial of Service via unnegotiated WebSocket compression. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-409. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 12 more. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; Red Hat Ansible Automation Platform Ansible Core 2; Red Hat Discovery 2; and 8 more.

CVE-2026-59881
Red Hat Enterprise Linux
Jul 30, 2026
Medium5.9Red Hat

Medium [CVE-2026-12996] Denial of Service or memory leak via crafted packets

Denial of Service or memory leak via crafted packets. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-825.

CVE-2026-12996
Unclassified
Jul 30, 2026
Medium5.3Red Hat

Medium [CVE-2026-11771] Denial of Service via crafted NTLM proxy response

Denial of Service via crafted NTLM proxy response. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-787.

CVE-2026-11771
Unclassified
Jul 30, 2026
Medium5.9Red Hat

Medium [CVE-2026-13117] Denial of service or memory leakage via incomplete TLS guard

Denial of service or memory leakage via incomplete TLS guard. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-825.

CVE-2026-13117
Unclassified
Jul 30, 2026
Medium5.3Apache

Medium [CVE-2026-23985] Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in the sql_parse.py component, specifically within the SQL_REGEX used for parsing SQL statements in the sqlparse library integration. The affected regular expression contains overlapping disjunctions that share a common outer quantifier. An authenticated attacker can exploit this by sending a maliciously crafted input string (specifically a long sequence of backslashes or similar characters) to endpoints that process SQL queries This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue.

CVE-2026-23985
Superset
Jul 30, 2026
Medium5.3Apache

Medium [CVE-2026-23981] Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboards they do not own

An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboards they do not own. When updating a chart's properties via the REST API, a user can provide a list of dashboard IDs (dashboards) to associate the chart with. The validation logic in the UpdateChartCommand failed to verify that the user had write permissions for the target dashboards specified in the request body. This issue affects Apache Superset: before 6.0.0. Users are recommended to upgrade to version 6.0.0, which fixes the issue.

CVE-2026-23981
Superset
Jul 30, 2026
Medium6.5Apache

Medium [CVE-2026-48910] carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim

A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. This issue affects Apache JSPWiki: through 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes the issue.

CVE-2026-48910
Unclassified
Jul 30, 2026
Medium6.5Apache

Medium [CVE-2024-31867 +1] LDAP filter injection vulnerability in Apache Zeppelin

LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped. This is an incomplete fix of CVE-2024-31867. This issue affects Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.

CVE-2024-31867CVE-2026-44617
Unclassified
Jul 30, 2026
Medium6.5Apache

Medium [CVE-2026-44616] LDAP injection vulnerability in Apache Zeppelin

LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint and potentially expose directory information. The role-lookup path was also affected after successful LDAP authentication. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.

CVE-2026-44616
Unclassified
Jul 30, 2026
Medium6.1Apache

Medium [CVE-2026-44613] Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling

Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a malicious site to perform actions on the user's behalf through REST and WebSocket endpoints. This issue affects Apache Zeppelin versions 0.6.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue.

CVE-2026-44613
Unclassified
Jul 30, 2026
Medium4.3Red Hat

Medium [CVE-2026-60074] Date::Manip: Incorrect date parsing leads to logic errors

Date::Manip: Incorrect date parsing leads to logic errors. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-681.

CVE-2026-60074
Unclassified
Jul 30, 2026
Medium5.5Red Hat

Medium [CVE-2026-7260] Denial of Service via circular symbolic links in phar archives

Denial of Service via circular symbolic links in phar archives. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:47200 with package php-main-8.5.9-1.hum1.

CVE-2026-7260
Unclassified
Jul 30, 2026
Medium5.8Red Hat

Medium [CVE-2026-18369] ACME HTTP-01 validation SSRF via IP literal identifiers and unvalidated redirects

ACME HTTP-01 validation SSRF via IP literal identifiers and unvalidated redirects. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-918.

CVE-2026-18369
Unclassified
Jul 30, 2026
Medium4.2VMware

Medium [CVE-2026-59328] Spring Boot: Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Bro…

Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

CVE-2026-59328
Tanzu / Spring
Jul 30, 2026
Medium4.4VMware

Medium [CVE-2026-59327] Spring Boot: Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain str…

Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse persists launch configuration attributes as cleartext XML, either to workspace metadata or, if the user marks the configuration as a shared file, directly into the project tree where it can be committed to version control. This secret is the sole credential protecting the DevTools remote restart/reload endpoint, which accepts and executes arbitrary class bytes on the target application. Anyone able to read the.launch file (via filesystem access, a workspace backup, or a shared VCS repository) can extract the secret and use it to achieve remote code execution against the associated Spring Boot application. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

CVE-2026-59327
Tanzu / Spring
Jul 30, 2026
Medium4.1Red Hat

Medium [CVE-2026-56850] mTLS client identities can be reused due to HTTPS Agent connection flaw

mTLS client identities can be reused due to HTTPS Agent connection flaw. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-56850
Unclassified
Jul 30, 2026
Medium6.3Red Hat

Medium [CVE-2026-58040] HTTPS Agent TLS session reuse skips hostname verification

HTTPS Agent TLS session reuse skips hostname verification. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-322. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-58040
Unclassified
Jul 30, 2026
Medium5.3Red Hat

Medium [CVE-2026-16531] Arbitrary file creation via path traversal in pmproxy logger servlet

Arbitrary file creation via path traversal in pmproxy logger servlet. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-16531
Unclassified
Jul 30, 2026