Skip to main content

CWE archive

CWE-436 CVEs

Programmatic archive

124 CVEs tagged with CWE-43614 Critical, 52 High, 45 Medium, 13 Low, 0 Unrated.

CVE-2026-49332

Published Jul 28, 2026

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys…

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-16221

Published Jul 19, 2026

Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an auth…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-63030

Published Jul 17, 2026

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (…

CVSS 9.8 · Critical
evidence mentions
27
Buzz score
93.0
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-44974

Published Jul 17, 2026

@hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrence of each duplicate parameter while Content.type() retained…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-47767

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gate…

CVSS 8.3 · High
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-45066

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, HtmlSanitizer URL sanitization…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-56329

Published Jul 10, 2026

Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding of double underscores to dots in preview hostname parsing.…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-56669

Published Jul 8, 2026

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to 1.4.29, Elysia uses getAll in form data n…

CVSS 7.5 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-59882

Published Jul 8, 2026

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters,…

CVSS 4.2 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-14198

Published Jul 1, 2026

@fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching middleware paths, while Fastify's underlying router preserve…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-13676

Published Jun 29, 2026

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on th…

CVSS 7.5 · High
evidence mentions
18
Buzz score
43.9
Vendor/product tagsBeta · best-effort

CVE-2026-53538

Published Jun 22, 2026

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addi…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53537

Published Jun 22, 2026

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53655

Published Jun 22, 2026

node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-48788

Published Jun 17, 2026

Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Versions 1.6.0 through 1.15.0 contain a Cross-Site Scripting (XSS)…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-42462

Published Jun 10, 2026

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of…

CVSS 7.0 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-47344

Published Jun 8, 2026

When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowin…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-40930

Published Jun 4, 2026

LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in t…

CVSS 5.4 · Medium
evidence mentions
5
Buzz score
30.9

CVE-2026-47076

Published May 25, 2026

Interpretation Conflict vulnerability in benoitc hackney allows Server Side Request Forgery. hackney_url:normalize/2 URL-decodes the host component after the URL has been parsed i…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-40165

Published May 21, 2026

authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameI…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-42551

Published May 13, 2026

Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Request::getMethod() unconditionally honors the X-HTTP-Method-Override header and the $_REQUEST['_method'] parame…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44576

Published May 13, 2026

Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to ca…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42177

Published May 12, 2026

linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest ru…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-42274

Published May 8, 2026

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normalized) request…

CVSS 7.8 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-42273

Published May 8, 2026

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs host matching in a case-sensitive manner, while HT…

CVSS 7.8 · High
evidence mentions
4
Buzz score
21.1
Showing 1-25 of 124 CVEsPage 1 of 5