CVE-2026-59000 to CVE-2026-59999
67 CVEs with public proof-of-concept exploits.
- CVE-2026-590941 PoCPathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Store
- CVE-2026-590951 PoCLobeChat < 2.2.10-canary.18 - SSRF via importFromUrl and fetchImageFromUrl
- CVE-2026-590971 PoCTaiga < 6.10.2 - Unauthorized Due-Date Creation via API Viewsets
- CVE-2026-590981 PoCLobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic Search
- CVE-2026-590991 PoCApereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
- CVE-2026-591001 PoCLobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Operations
- CVE-2026-591021 PoCForgejo < 15.0.3 - Stored XSS via Actions Run Full Name Rendering
- CVE-2026-591121 PoCSignature validation vulnerability affecting DigiDoc applications
- CVE-2026-591971 PoCPillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
- CVE-2026-591981 PoCPillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
- CVE-2026-591991 PoCPillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
- CVE-2026-592031 PoCPillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
- CVE-2026-592041 PoCPillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
- CVE-2026-592051 PoCPillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch
- CVE-2026-592131 PoCOpen WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
- CVE-2026-592171 PoCOpen WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
- CVE-2026-592201 PoCOpen WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
- CVE-2026-592211 PoCopen-webui terminal proxy path traversal guard bypass via 9x encoded traversal
- CVE-2026-592221 PoCOpen WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
- CVE-2026-592271 PoCOpen WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
- CVE-2026-592301 PoCApache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when…
- CVE-2026-592431 PoCApache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature`…
- CVE-2026-592551 PoCBloodHound Missing Authorization on Custom Node Management API
- CVE-2026-592581 PoCimmich < 3.0.3 Shared Album Editor Ownership Takeover via updateUser
- CVE-2026-593104 PoCsKEVvCenter directory-traversal vulnerability
- CVE-2026-597141 PoCOpen WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
- CVE-2026-597261 PoCRuflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
- CVE-2026-597271 PoCAstro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
- CVE-2026-597281 PoC@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
- CVE-2026-597291 PoCAstro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
- CVE-2026-597311 PoCAstro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
- CVE-2026-597321 PoCrclone archive extract allows S3 destination prefix escape via crafted archive paths
- CVE-2026-597331 PoCrclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete…
- CVE-2026-597341 PoCCoolify: OS Command Injection in Health Check Configuration Allows Remote Code Execution
- CVE-2026-597631 PoCUnbounded Arch package file metadata can cause resource amplification in Gitea package uploads
- CVE-2026-598001 PoC9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint
- CVE-2026-598011 PoC9Router 0.4.41 - Unauthenticated API Exposure via /api/providers
- CVE-2026-598021 PoCPasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push Payload
- CVE-2026-598031 PoCrpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocol
- CVE-2026-598041 PoCMidscene Bridge Server - Session Hijack via Unauthenticated WebSocket
- CVE-2026-598061 PoCGradio < 6.20.0 - Open Redirect and SSRF via /gradio_api/file= endpoint
- CVE-2026-598071 PoCComposio SDK < 0.2.32-beta.283 - Sensitive File Upload via tool-file-uploads.ts
- CVE-2026-598341 PoCSiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
- CVE-2026-598681 PoCjs-yaml: YAML merge-key chains can force quadratic CPU consumption
- CVE-2026-598691 PoCjs-yaml: YAML merge-key chains can force quadratic CPU consumption
- CVE-2026-598701 PoCjs-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing
- CVE-2026-598711 PoCnode-tar: Process crash via PAX numeric path type confusion
- CVE-2026-598731 PoCnode-tar: Decompression/parse DoS via unlimited input
- CVE-2026-598741 PoCnode-tar: Negative tar entry size causes infinite loop in archive replace
- CVE-2026-598791 PoCImmutable.js `List` 32-bit trie overflow → unrecoverable DoS
- CVE-2026-598871 PoClinkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
- CVE-2026-598901 PoCsetuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
- CVE-2026-598921 PoCOpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
- CVE-2026-598931 PoCsqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
- CVE-2026-599191 PoCNetty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
- CVE-2026-599201 PoCNetty: STOMP CONNECT Frame Header Injection
- CVE-2026-599211 PoCNetty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
- CVE-2026-599221 PoCMistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
- CVE-2026-599241 PoCMistune: Arbitrary File Read via Include directive path traversal
- CVE-2026-599251 PoCinline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
- CVE-2026-599271 PoCMistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two…
- CVE-2026-599311 PoCPhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
- CVE-2026-599391 PoChttplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
- CVE-2026-599411 PoCDompdf: Uncontrolled resource consumption based on declared BMP dimensions
- CVE-2026-599421 PoCDompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
- CVE-2026-599431 PoCDompdf: Embedded SVG images can leak existence of files and directories within the filesystem
- CVE-2026-599921 PoCTina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)