Skip to content

Commit 4f4d964

Browse files
Sync EUVD catalog: Mon Jun 15 01:03:02 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent bdb983e commit 4f4d964

18 files changed

Lines changed: 783 additions & 1 deletion
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
{
2+
"id": "EUVD-2025-210137",
3+
"enisaUuid": "1a2b6020-6807-39bd-9b7d-549f7212d03f",
4+
"description": "The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to \"maintain both.\" Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file write operation, an authenticated attacker can overwrite files uploaded by other users.",
5+
"datePublished": "Jun 14, 2026, 6:00:03 AM",
6+
"dateUpdated": "Jun 14, 2026, 6:00:03 AM",
7+
"baseScore": 0.0,
8+
"references": "https://wpscan.com/vulnerability/06e33418-1644-49a1-b012-122046604109/\n",
9+
"aliases": "CVE-2025-15546\nGHSA-xwgf-8969-9fm2\n",
10+
"assigner": "WPScan",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "d542d4ef-c332-3775-9d22-341ea948b054",
15+
"product": {
16+
"name": "Iptanus File Upload",
17+
"vendor": {
18+
"name": "nickboss"
19+
}
20+
},
21+
"product_version": "0 <5.1.7"
22+
}
23+
],
24+
"enisaIdVendor": [
25+
{
26+
"id": "66e5b3fb-f5ad-3c5f-9e91-2d1611e46e1e",
27+
"vendor": {
28+
"name": "Unknown"
29+
}
30+
}
31+
]
32+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-36657",
3+
"enisaUuid": "a9525c03-bc07-340e-a01a-ace3bf75f4ea",
4+
"description": "LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.",
5+
"datePublished": "Jun 14, 2026, 3:23:12 AM",
6+
"dateUpdated": "Jun 14, 2026, 3:23:12 AM",
7+
"baseScore": 8.5,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
10+
"references": "https://www.litespeedtech.com/products/litespeed-web-server/control-panel-support/cpanel\nhttps://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/\n",
11+
"aliases": "CVE-2026-54420\nGHSA-3g44-c4qc-cxm8\n",
12+
"assigner": "mitre",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "6a2a60d4-5f15-3efc-8292-854ed02b992d",
17+
"product": {
18+
"name": "cPanel Plugin",
19+
"vendor": {
20+
"name": "LiteSpeed Technologies"
21+
}
22+
},
23+
"product_version": "2.3 <2.4.8"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "8695f841-455f-3a00-90b8-8cd8e76650cb",
29+
"vendor": {
30+
"name": "LiteSpeed Technologies"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-36658",
3+
"enisaUuid": "c99ff0ab-1603-3beb-9962-d10dd5c9f3b0",
4+
"description": "In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.",
5+
"datePublished": "Jun 14, 2026, 3:49:37 AM",
6+
"dateUpdated": "Jun 14, 2026, 3:49:37 AM",
7+
"baseScore": 6.8,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
10+
"references": "https://bugs.launchpad.net/ironic/+bug/2155049\n",
11+
"aliases": "CVE-2026-54421\nGHSA-j4cw-mcg2-2q78\n",
12+
"assigner": "mitre",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "740d7cbd-b60d-333c-b418-bee4acc587c7",
17+
"product": {
18+
"name": "Ironic",
19+
"vendor": {
20+
"name": "OpenStack"
21+
}
22+
},
23+
"product_version": "0 \u226435.0.1"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "f88b3d93-e095-3bfb-a500-c08f2bcb7508",
29+
"vendor": {
30+
"name": "OpenStack"
31+
}
32+
}
33+
]
34+
}
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
{
2+
"id": "EUVD-2026-36659",
3+
"enisaUuid": "e4e7b43c-f9f8-3b95-91ac-62ab4bcf139a",
4+
"description": "GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle.\n\nGD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe (\"| cmd\", \"cmd |\") or begins with a redirect (\"> path\", \">> path\") is run as a command or redirect rather than opened as a file. _make_filehandle is the single open path behind every filename-accepting constructor (new, newFromPng, newFromJpeg, and the rest); the in-memory *Data variants do not open a path and are unaffected.\n\nAny caller that forwards untrusted input to one of these constructors as a pathname can run an arbitrary command or truncate a file under the process UID.",
5+
"datePublished": "Jun 14, 2026, 11:39:21 AM",
6+
"dateUpdated": "Jun 14, 2026, 11:28:27 PM",
7+
"baseScore": 0.0,
8+
"references": "https://github.com/lstein/Perl-GD/commit/67b163713c6c78dfeb693da0978ae934e5cd8210.patch\nhttps://metacpan.org/release/RURBAN/GD-2.86/changes\n",
9+
"aliases": "GHSA-hx22-9fx3-xg77\nCVE-2026-11526\n",
10+
"assigner": "CPANSec",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "abb25d60-6a6b-393e-b401-8194e34b4b52",
15+
"product": {
16+
"name": "gd",
17+
"vendor": {
18+
"name": "Microsoft"
19+
}
20+
},
21+
"product_version": "0 <2.86"
22+
}
23+
],
24+
"enisaIdVendor": [
25+
{
26+
"id": "bf2294c2-3c59-3f0f-8f6b-2f864cd06b26",
27+
"vendor": {
28+
"name": "RURBAN"
29+
}
30+
}
31+
]
32+
}
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
{
2+
"id": "EUVD-2026-36660",
3+
"enisaUuid": "fb3ed9d7-d770-3779-83b0-61457ddf1103",
4+
"description": "Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle.\n\nConfig::IniFiles::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe (\"| cmd\", \"cmd |\") or begins with a redirect (\"> path\", \">> path\") is run as a command or redirect rather than opened as a file. The helper is the open path behind the documented -file argument: new(-file => $thing) reaches it through ReadConfig. An in-memory scalar reference (-file => \\$text) does not open a path and is unaffected.\n\nAny caller that forwards untrusted input to the -file argument can run an arbitrary command or truncate a file under the process UID.",
5+
"datePublished": "Jun 14, 2026, 11:40:45 AM",
6+
"dateUpdated": "Jun 14, 2026, 11:28:28 PM",
7+
"baseScore": 0.0,
8+
"references": "https://github.com/shlomif/perl-Config-IniFiles/commit/3e48f9627fbba4dae5de35be1f735cdeb7e47fb8.patch\nhttps://metacpan.org/release/SHLOMIF/Config-IniFiles-3.001000/changes\n",
9+
"aliases": "GHSA-2g88-7qc8-9vxv\nCVE-2026-11527\n",
10+
"assigner": "CPANSec",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "aa77586d-d677-3f44-b177-7a12b2ed9d54",
15+
"product": {
16+
"name": "Config::IniFiles",
17+
"vendor": {
18+
"name": "SHLOMIF"
19+
}
20+
},
21+
"product_version": "0 <3.001000"
22+
}
23+
],
24+
"enisaIdVendor": [
25+
{
26+
"id": "af035431-8632-3003-97c9-b1b2ffbcc38b",
27+
"vendor": {
28+
"name": "SHLOMIF"
29+
}
30+
}
31+
]
32+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-36661",
3+
"enisaUuid": "b5b1ee6f-b045-32c7-8116-ed08d37c00f3",
4+
"description": "nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header() function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte receive buffer by sending a crafted MBAP frame whose Length field is set to 255. The overflow corrupts the adjacent buffer-index field of the nanoMODBUS state structure, resulting in denial of service through invalid memory accesses and, on bare-metal and RTOS targets without memory protection, one-byte information disclosure and writes to unintended register addresses on the Write Multiple Registers (FC16) handler path.",
5+
"datePublished": "Jun 14, 2026, 5:10:12 PM",
6+
"dateUpdated": "Jun 14, 2026, 5:10:12 PM",
7+
"baseScore": 7.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/AU:Y",
10+
"references": "https://github.com/debevv/nanoMODBUS\nhttps://github.com/debevv/nanoMODBUS/blob/v1.23.0/nanomodbus.c#L369\nhttps://cwe.mitre.org/data/definitions/193.html\nhttps://cwe.mitre.org/data/definitions/787.html\n",
11+
"aliases": "GHSA-6f53-f2m4-6j2h\nCVE-2026-54410\n",
12+
"assigner": "TuranSec",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "d588bdd8-7e7b-3efb-aad0-cf10d7a8f705",
17+
"product": {
18+
"name": "nanoMODBUS",
19+
"vendor": {
20+
"name": "debevv"
21+
}
22+
},
23+
"product_version": "0 \u22641.23.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "0ba0e085-f4ce-38db-a9dc-3b4b75f43898",
29+
"vendor": {
30+
"name": "debevv"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-36662",
3+
"enisaUuid": "15570ff5-30c2-33c8-b419-1a50a6e1715a",
4+
"description": "Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.",
5+
"datePublished": "Jun 14, 2026, 5:21:43 PM",
6+
"dateUpdated": "Jun 14, 2026, 5:21:43 PM",
7+
"baseScore": 6.9,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/AU:N/V:D",
10+
"references": "https://github.com/linux-pam/linux-pam\nhttps://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327\nhttps://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h\nhttps://cwe.mitre.org/data/definitions/208.html\n",
11+
"aliases": "GHSA-56gg-22rq-q53x\nCVE-2026-54411\n",
12+
"assigner": "TuranSec",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "e5c30781-4d07-3d3e-a583-ec3ee118805f",
17+
"product": {
18+
"name": "Linux-PAM",
19+
"vendor": {
20+
"name": "Linux-PAM"
21+
}
22+
},
23+
"product_version": "0 \u22641.7.2"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "6b5fd301-7bfb-3691-be5a-8173e6e717ab",
29+
"vendor": {
30+
"name": "Linux-PAM"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-36663",
3+
"enisaUuid": "f380d99c-3b02-3661-930f-dded05f42d50",
4+
"description": "LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response() function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an unencrypted session - to crash a subscribed MQTT-C client and potentially disclose adjacent heap memory by sending a single crafted PUBLISH packet. The function validates only that the fixed-header remaining_length is at least 4, then reads the 16-bit topic_name_size field from the broker-controlled packet and advances the parse pointer by that value without verifying that topic_name_size plus the surrounding overhead fits within remaining_length; it subsequently computes application_message_size as remaining_length - topic_name_size - 2 (QoS 0) or - 4 (QoS greater than 0) in unsigned arithmetic, producing an integer underflow that is then passed to memmove(). A PUBLISH packet with topic_name_size = 0xFFFF and remaining_length = 7 advances the parse pointer 65535 bytes past the receive buffer (out-of-bounds read) and causes an application_message_size near 2^32, crashing the process when the resulting memmove() is executed.",
5+
"datePublished": "Jun 14, 2026, 5:26:36 PM",
6+
"dateUpdated": "Jun 14, 2026, 5:27:35 PM",
7+
"baseScore": 7.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/AU:Y/V:D",
10+
"references": "https://github.com/LiamBindle/MQTT-C\nhttps://github.com/LiamBindle/MQTT-C/blob/v1.1.6/src/mqtt.c#L1334\nhttps://cwe.mitre.org/data/definitions/125.html\nhttps://cwe.mitre.org/data/definitions/191.html\n",
11+
"aliases": "CVE-2026-54412\nGHSA-28cw-rpqc-wqqj\n",
12+
"assigner": "TuranSec",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "e3becf44-98d1-36da-956e-7c822d8c6f08",
17+
"product": {
18+
"name": "MQTT-C",
19+
"vendor": {
20+
"name": "LiamBindle"
21+
}
22+
},
23+
"product_version": "0 \u22641.1.6"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "3f8e2153-2eae-358e-a6f4-85a3b43735e2",
29+
"vendor": {
30+
"name": "LiamBindle"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-36664",
3+
"enisaUuid": "9ee43b61-fb7f-33a9-beb1-e9dbbc9602a0",
4+
"description": "driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess() function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potentially read memory past the receive buffer by sending a single-byte 0x27 SecurityAccess request that follows any earlier well-formed 0x27 message. The handler reads the SecurityAccess subFunction from recv_buf[1] without first checking that recv_len is at least 2, then computes the key-data length as the unsigned subtraction (uint16_t)(recv_len - UDS_0X27_REQ_BASE_LEN); when recv_len equals 1 the result underflows to 65535 and is passed as args.len to the application's SecAccessValidateKey or SecAccessRequestSeed callback, which typically iterates or copies that many bytes from the 4-KB receive buffer. Every other UDS sub-function handler in the library (0x10, 0x11, 0x14, 0x19, 0x22, 0x23, 0x28, and others) performs an explicit recv_len lower-bound check before indexing; Handle_0x27_SecurityAccess is the sole outlier. The vulnerable handler reaches over CAN bus, OBD-II, ISO-TP, and DoIP transports and is exposed in the default diagnostic session without prior authentication; deployments on automotive ECUs, industrial controllers, and IoT devices that ship iso14229 as their UDS server are affected.",
5+
"datePublished": "Jun 14, 2026, 5:38:16 PM",
6+
"dateUpdated": "Jun 14, 2026, 5:38:16 PM",
7+
"baseScore": 7.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/AU:Y/V:D",
10+
"references": "https://github.com/driftregion/iso14229\nhttps://github.com/driftregion/iso14229/blob/main/iso14229.c#L1447\nhttps://cwe.mitre.org/data/definitions/191.html\nhttps://cwe.mitre.org/data/definitions/125.html\n",
11+
"aliases": "GHSA-36r7-c6f4-gj9g\nCVE-2026-54413\n",
12+
"assigner": "TuranSec",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "08c47181-bb7a-315a-b5d5-d885747f871e",
17+
"product": {
18+
"name": "iso14229",
19+
"vendor": {
20+
"name": "driftregion"
21+
}
22+
},
23+
"product_version": "0 \u22640.9.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "78cdb986-883d-307d-b6b2-4c20f74f6aed",
29+
"vendor": {
30+
"name": "driftregion"
31+
}
32+
}
33+
]
34+
}

0 commit comments

Comments
 (0)