Search: "canonical"

158 CVEs found

CVE-2026-39858
10.0 CRITICAL

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet...

Published: 2026-04-30
Products: 6
Vendors:
traefik
CVE-2026-42085
4.3 MEDIUM

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in ...

Published: 2026-05-04
Products: 3
Vendors:
openc3

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be...

Published: 2026-05-06
Products: 0
CVE-2026-44111
4.3 MEDIUM

OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allows callers to read any Markdown files within the workspace root. Attackers with ...

Published: 2026-05-06
Products: 1
Vendors:
openclaw

PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5.4, apps/web/src/routes/skills.ts exposes an authenticated endpoint POST /api/ski...

Published: 2026-05-08
Products: 1
Vendors:
legeling

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.getName()) with no canonical-path check. An entry n...

Published: 2026-05-12
Products: 0
CVE-2026-44288
5.3 MEDIUM

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded t...

Published: 2026-05-13
Products: 2
Vendors:
protobufjs_project

phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks permission filtering, allowing unauthenticated attackers to enumerate restricted F...

Published: 2026-05-15
Products: 0
CVE-2026-44837
5.9 MEDIUM

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file p...

Published: 2026-05-26
Products: 1
Vendors:
viewcomponent
CVE-2026-47118
6.5 MEDIUM

Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by supplying crafted paths to the image file serving endpoint, whic...

Published: 2026-05-27
Products: 0

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verifica...

Published: 2026-05-27
Products: 4
Vendors:
erlang

An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd dae...

Published: 2026-05-28
Products: 2
Vendors:
canonical apple

An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment b...

Published: 2026-05-28
Products: 1
Vendors:
canonical

Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow and LocalStorage::MapUTF8 within the local storage plugin, where the on-disk path...

Published: 2026-05-28
Products: 0

Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ...

Published: 2026-06-02
Products: 0

Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security...

Published: 2026-06-02
Products: 0

unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This...

Published: 2026-06-03
Products: 0

OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identiti...

Published: 2026-06-11
Products: 1
Vendors:
openclaw