Skip to content

Commit e1fa268

Browse files
Sync EUVD catalog: Tue Jul 21 00:38:14 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 6833d28 commit e1fa268

370 files changed

Lines changed: 11514 additions & 418 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2026/05/EUVD-2026-33274.json

Lines changed: 23 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,15 +3,25 @@
33
"enisaUuid": "7dda2317-88fe-356d-a32c-eafd01df48b2",
44
"description": "A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.",
55
"datePublished": "May 29, 2026, 9:50:44 AM",
6-
"dateUpdated": "Jul 15, 2026, 12:50:13 AM",
6+
"dateUpdated": "Jul 20, 2026, 1:28:50 AM",
77
"baseScore": 7.4,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
10-
"references": "https://access.redhat.com/errata/RHSA-2026:27009\nhttps://access.redhat.com/errata/RHSA-2026:27044\nhttps://access.redhat.com/errata/RHSA-2026:27063\nhttps://access.redhat.com/security/cve/CVE-2026-46579\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2483181\n",
10+
"references": "https://access.redhat.com/errata/RHSA-2026:27009\nhttps://access.redhat.com/errata/RHSA-2026:27044\nhttps://access.redhat.com/errata/RHSA-2026:27063\nhttps://access.redhat.com/errata/RHSA-2026:37580\nhttps://access.redhat.com/security/cve/CVE-2026-46579\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2483181\n",
1111
"aliases": "CVE-2026-46579\nGHSA-ccmj-8c3p-4qwj\n",
1212
"assigner": "redhat",
13-
"epss": 0.23,
13+
"epss": 0.24,
1414
"enisaIdProduct": [
15+
{
16+
"id": "01d1af5b-84ab-3387-b2b7-5e3cfd6b1e5a",
17+
"product": {
18+
"name": "Red Hat OpenShift Container Platform 4.2",
19+
"vendor": {
20+
"name": "Red Hat"
21+
}
22+
},
23+
"product_version": "patch: 1781639027"
24+
},
1525
{
1626
"id": "055fa2d9-202e-3de9-a71c-b3e9281c038b",
1727
"product": {
@@ -22,6 +32,16 @@
2232
},
2333
"product_version": "patch: 1781639027"
2434
},
35+
{
36+
"id": "3d33853a-8a8d-35f3-8e87-b6303a5ebbc4",
37+
"product": {
38+
"name": "Red Hat OpenShift Container Platform 4.19",
39+
"vendor": {
40+
"name": "Red Hat"
41+
}
42+
},
43+
"product_version": "patch: 1783445642"
44+
},
2545
{
2646
"id": "61b5f1f6-1a07-3f2f-807a-6eff3d7f6af0",
2747
"product": {

advisories/2026/06/EUVD-2026-33883.json

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "c3c35bed-65bc-3719-839f-23826199a796",
44
"description": "The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.",
55
"datePublished": "Jun 2, 2026, 7:22:26 AM",
6-
"dateUpdated": "Jul 15, 2026, 1:21:06 AM",
6+
"dateUpdated": "Jul 20, 2026, 2:05:17 AM",
77
"baseScore": 8.8,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
@@ -52,6 +52,16 @@
5252
},
5353
"product_version": "patch: 1780444348"
5454
},
55+
{
56+
"id": "7483e9d6-bd33-39ae-962e-9df1f97416e8",
57+
"product": {
58+
"name": "Red Hat OpenShift Container Platform 4.2",
59+
"vendor": {
60+
"name": "Red Hat"
61+
}
62+
},
63+
"product_version": "patch: 1780990977"
64+
},
5565
{
5666
"id": "9c5a8b1c-3bac-3bab-ad28-f2d339c5dede",
5767
"product": {
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"id": "EUVD-2025-203029",
3+
"enisaUuid": "8bef7819-ec26-3291-a2a1-e6c7a304f457",
4+
"description": "Tornado: Quadratic DoS via Crafted Multipart Parameters",
5+
"datePublished": "Jul 20, 2026, 6:57:54 PM",
6+
"dateUpdated": "Jul 20, 2026, 6:57:54 PM",
7+
"baseScore": 7.5,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
10+
"references": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-jhmp-mqwm-3gq8\nhttps://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd\nhttps://github.com/tornadoweb/tornado/releases/tag/v6.5.3\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-67726\nhttps://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2025-267.yaml\n",
11+
"aliases": "CVE-2025-67726\nPYSEC-2025-267\nGHSA-jhmp-mqwm-3gq8\n",
12+
"assigner": "GitHub_M",
13+
"epss": 0.38,
14+
"enisaIdProduct": [
15+
{
16+
"id": "1a2ac0c1-b9ce-3a56-bf39-1842a01f2662",
17+
"product": {
18+
"name": "Tornado",
19+
"vendor": {
20+
"name": "tornadoweb"
21+
}
22+
},
23+
"product_version": "< 6.5.3"
24+
},
25+
{
26+
"id": "76d9bb64-9eb7-3ff8-b352-e23bfb618f2f",
27+
"product": {
28+
"name": "Tornado",
29+
"vendor": {
30+
"name": "tornadoweb"
31+
}
32+
},
33+
"product_version": "< 6.5.3"
34+
}
35+
],
36+
"enisaIdVendor": [
37+
{
38+
"id": "274692ea-3644-3260-9bbc-2827e2a45a84",
39+
"vendor": {
40+
"name": "tornadoweb"
41+
}
42+
}
43+
]
44+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"id": "EUVD-2025-203031",
3+
"enisaUuid": "75af1a92-484a-3854-bcf8-35d83af0efb3",
4+
"description": "Tornado: Quadratic DoS via Repeated Header Coalescing",
5+
"datePublished": "Jul 20, 2026, 6:57:34 PM",
6+
"dateUpdated": "Jul 20, 2026, 6:57:34 PM",
7+
"baseScore": 7.5,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
10+
"references": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c98p-7wgm-6p64\nhttps://github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd\nhttps://github.com/tornadoweb/tornado/releases/tag/v6.5.3\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-67725\nhttps://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2025-266.yaml\n",
11+
"aliases": "PYSEC-2025-266\nGHSA-c98p-7wgm-6p64\nCVE-2025-67725\n",
12+
"assigner": "GitHub_M",
13+
"epss": 0.4,
14+
"enisaIdProduct": [
15+
{
16+
"id": "1d2cdce0-4aa0-3c81-8770-49fa5ce055d9",
17+
"product": {
18+
"name": "Tornado",
19+
"vendor": {
20+
"name": "tornadoweb"
21+
}
22+
},
23+
"product_version": "< 6.5.3"
24+
},
25+
{
26+
"id": "ff60a6b8-7ec1-351b-ae81-6e81b889dbaf",
27+
"product": {
28+
"name": "Tornado",
29+
"vendor": {
30+
"name": "tornadoweb"
31+
}
32+
},
33+
"product_version": "< 6.5.3"
34+
}
35+
],
36+
"enisaIdVendor": [
37+
{
38+
"id": "e1e2007d-159f-3698-8063-b3b0b9f32287",
39+
"vendor": {
40+
"name": "tornadoweb"
41+
}
42+
}
43+
]
44+
}
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
{
2+
"id": "EUVD-2025-203032",
3+
"enisaUuid": "8c97bb7b-5085-330d-9072-ba1fd713ca88",
4+
"description": "Tornado vulnerable to Header Injection and XSS via reason argument",
5+
"datePublished": "Jul 20, 2026, 6:55:11 PM",
6+
"dateUpdated": "Jul 20, 2026, 6:55:11 PM",
7+
"baseScore": 5.4,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
10+
"references": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-pr2v-jx2c-wg9f\nhttps://github.com/tornadoweb/tornado/commit/9c163aebeaad9e6e7d28bac1f33580eb00b0e421\nhttps://github.com/tornadoweb/tornado/releases/tag/v6.5.3\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-67724\nhttps://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2025-265.yaml\n",
11+
"aliases": "PYSEC-2025-265\nGHSA-pr2v-jx2c-wg9f\nCVE-2025-67724\n",
12+
"assigner": "GitHub_M",
13+
"epss": 0.19,
14+
"enisaIdProduct": [
15+
{
16+
"id": "535c0303-1a5d-3475-a7bc-9a47adf6344c",
17+
"product": {
18+
"name": "Tornado",
19+
"vendor": {
20+
"name": "tornadoweb"
21+
}
22+
},
23+
"product_version": "< 6.5.3"
24+
},
25+
{
26+
"id": "ffa6f8df-fda7-32ee-b04d-60ff17304863",
27+
"product": {
28+
"name": "Tornado",
29+
"vendor": {
30+
"name": "tornadoweb"
31+
}
32+
},
33+
"product_version": "< 6.5.3"
34+
}
35+
],
36+
"enisaIdVendor": [
37+
{
38+
"id": "d4e7953d-90da-3f83-a858-25de8f824c15",
39+
"vendor": {
40+
"name": "tornadoweb"
41+
}
42+
}
43+
]
44+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-39180",
3+
"enisaUuid": "7503493b-1409-3618-a353-6e5815b5428c",
4+
"description": "shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)",
5+
"datePublished": "Jul 20, 2026, 9:49:34 PM",
6+
"dateUpdated": "Jul 20, 2026, 9:49:34 PM",
7+
"baseScore": 8.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://github.com/ljharb/shell-quote/security/advisories/GHSA-395f-4hp3-45gv\nhttps://www.npmjs.com/package/shell-quote\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-13311\nhttps://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\nhttps://github.com/ljharb/shell-quote/releases/tag/v1.9.0\n",
11+
"aliases": "CVE-2026-13311\nGHSA-395f-4hp3-45gv\n",
12+
"assigner": "harborist",
13+
"epss": 0.36,
14+
"enisaIdProduct": [
15+
{
16+
"id": "7544bed7-62ba-361b-b686-5a94fd2f09ec",
17+
"product": {
18+
"name": "shell-quote",
19+
"vendor": {
20+
"name": "ljharb"
21+
}
22+
},
23+
"product_version": "0 \u22641.8.4"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "e02261e0-2e64-3d53-8102-e6b6336fc816",
29+
"vendor": {
30+
"name": "ljharb"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-39539",
3+
"enisaUuid": "f35c1cc7-3a7a-32d7-b382-fd9660d77a96",
4+
"description": "File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup",
5+
"datePublished": "Jul 20, 2026, 9:17:24 PM",
6+
"dateUpdated": "Jul 20, 2026, 9:17:24 PM",
7+
"baseScore": 8.2,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H",
10+
"references": "https://github.com/filebrowser/filebrowser/security/advisories/GHSA-fmm7-x4gx-8jhr\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55667\nhttps://github.com/filebrowser/filebrowser/blob/be23ab3a15bf957928ecfed88de5ab67850c1b9c/http/resource.go#L172-L174\n",
11+
"aliases": "GHSA-fmm7-x4gx-8jhr\nCVE-2026-55667\n",
12+
"assigner": "GitHub_M",
13+
"epss": 0.36,
14+
"enisaIdProduct": [
15+
{
16+
"id": "b88130fe-ef9f-3425-9b2d-d38ed4fdb163",
17+
"product": {
18+
"name": "filebrowser",
19+
"vendor": {
20+
"name": "gtsteffaniak"
21+
}
22+
},
23+
"product_version": "< 2.63.16"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "6e039144-d54d-3f00-810a-e315806a9497",
29+
"vendor": {
30+
"name": "filebrowser"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2026-40269",
3+
"enisaUuid": "903adc42-9bc5-31a0-a663-9a244b1710bb",
4+
"description": "brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups",
5+
"datePublished": "Jul 20, 2026, 8:51:09 PM",
6+
"dateUpdated": "Jul 20, 2026, 8:51:10 PM",
7+
"baseScore": 7.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/S:N/AU:Y/R:U/V:D/RE:M/U:Amber",
10+
"references": "https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754\nhttps://www.npmjs.com/package/brace-expansion\nhttps://github.com/juliangruber/brace-expansion/security/advisories/GHSA-3jxr-9vmj-r5cp\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-13149\nhttps://github.com/juliangruber/brace-expansion/pull/122\nhttps://github.com/juliangruber/brace-expansion/pull/123\nhttps://github.com/juliangruber/brace-expansion/commit/835d6be91201122d9adffb0c0c8c094189ace265\nhttps://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\nhttps://github.com/juliangruber/brace-expansion/releases/tag/v1.1.16\nhttps://github.com/juliangruber/brace-expansion/releases/tag/v2.1.2\nhttps://github.com/juliangruber/brace-expansion/releases/tag/v5.0.7\n",
11+
"aliases": "CVE-2026-13149\nGHSA-3jxr-9vmj-r5cp\n",
12+
"assigner": "seal",
13+
"epss": 0.36,
14+
"enisaIdProduct": [
15+
{
16+
"id": "c5005b5f-a2a8-36e5-be2a-a0b03ffba2a6",
17+
"product": {
18+
"name": "brace-expansion",
19+
"vendor": {
20+
"name": "juliangruber"
21+
}
22+
},
23+
"product_version": "0 \u22645.0.6"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "13fb66d1-585a-3f8c-b0c6-75ad21ecf82b",
29+
"vendor": {
30+
"name": "juliangruber"
31+
}
32+
}
33+
]
34+
}

advisories/2026/07/EUVD-2026-41558.json

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,16 @@
11
{
22
"id": "EUVD-2026-41558",
33
"enisaUuid": "b4c97704-e2f9-307c-8fbd-50f135d833ba",
4-
"description": "webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page. Any website a developer visits while the dev server is running can trigger these endpoints cross-origin with no interaction beyond the visit. An attacker can open an arbitrary existing local file in the developer's editor, including files outside the project root, and repeated requests can spawn editor processes and force recompilations that degrade the developer's machine. Patches: upgrade to webpack-dev-server 5.2.6. Workarounds: none.",
5-
"datePublished": "Jul 3, 2026, 5:00:00 PM",
6-
"dateUpdated": "Jul 3, 2026, 5:00:00 PM",
4+
"description": "webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints",
5+
"datePublished": "Jul 20, 2026, 10:01:56 PM",
6+
"dateUpdated": "Jul 20, 2026, 10:01:56 PM",
77
"baseScore": 4.7,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L",
10-
"references": "https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-f5vj-f2hx-8m93\nhttps://cna.openjsf.org/security-advisories.html\n",
11-
"aliases": "CVE-2026-14620\n",
10+
"references": "https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-f5vj-f2hx-8m93\nhttps://cna.openjsf.org/security-advisories.html\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-14620\nhttps://github.com/webpack/webpack-dev-server/pull/5698\nhttps://github.com/webpack/webpack-dev-server/commit/80cd9eea54975fe632a518d8bd902a260f374e7c\nhttps://github.com/webpack/webpack-dev-server/releases/tag/v5.2.6\n",
11+
"aliases": "CVE-2026-14620\nGHSA-f5vj-f2hx-8m93\n",
1212
"assigner": "openjs",
13-
"epss": 0.0,
13+
"epss": 0.12,
1414
"enisaIdProduct": [
1515
{
1616
"id": "8513d7f6-58a9-38c1-aeb8-d17e385f196e",

advisories/2026/07/EUVD-2026-41559.json

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,16 @@
11
{
22
"id": "EUVD-2026-41559",
33
"enisaUuid": "e205f871-57bd-3fd2-ac72-ebc8b0bcd85f",
4-
"description": "webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malformed Origin header. The malformed value causes an uncaught exception in the host-validation path and crashes the dev server. Impact is limited to availability of the development server, no data disclosure, no code execution. Patches: upgrade to webpack-dev-server 5.2.6. Workarounds: keep the dev server bound to localhost (the default) and do not expose it to untrusted networks.",
5-
"datePublished": "Jul 3, 2026, 5:23:41 PM",
6-
"dateUpdated": "Jul 3, 2026, 5:23:41 PM",
4+
"description": "webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header",
5+
"datePublished": "Jul 20, 2026, 10:02:31 PM",
6+
"dateUpdated": "Jul 20, 2026, 10:02:31 PM",
77
"baseScore": 5.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
10-
"references": "https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-m28w-2pqf-7qgj\nhttps://cna.openjsf.org/security-advisories.html\n",
11-
"aliases": "CVE-2026-14631\n",
10+
"references": "https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-m28w-2pqf-7qgj\nhttps://cna.openjsf.org/security-advisories.html\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-14631\nhttps://github.com/webpack/webpack-dev-server/pull/5699\nhttps://github.com/webpack/webpack-dev-server/commit/f21ed0f44aceb6132abb591ee8b60d770b6e489f\n",
11+
"aliases": "CVE-2026-14631\nGHSA-m28w-2pqf-7qgj\n",
1212
"assigner": "openjs",
13-
"epss": 0.0,
13+
"epss": 0.31,
1414
"enisaIdProduct": [
1515
{
1616
"id": "90884ebd-e5d7-31b9-8994-992979a9c58c",

0 commit comments

Comments
 (0)