Skip to content

Commit d3849ff

Browse files

File tree

Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-3fwg-9p8x-37mv",
4+
"modified": "2026-09-20T00:30:23Z",
5+
"published": "2026-09-20T00:30:23Z",
6+
"aliases": [
7+
"CVE-2026-93991"
8+
],
9+
"details": "Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "WEB",
24+
"url": "https://github.com/argoproj/argo-workflows/security/advisories/GHSA-q65w-j2vp-47c4"
25+
},
26+
{
27+
"type": "ADVISORY",
28+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93991"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/argoproj/argo-workflows/commit/a40972386c097ddf816d2e60e13f058bedca53d9"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/argoproj/argo-workflows"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/argoproj/argo-workflows/releases/tag/v4.1.4"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://www.vulncheck.com/advisories/argo-workflows-4.1.0-through-4.1.3-cross-namespace-disclosure-via-negated-selector"
45+
}
46+
],
47+
"database_specific": {
48+
"cwe_ids": [
49+
"CWE-639"
50+
],
51+
"severity": "HIGH",
52+
"github_reviewed": false,
53+
"github_reviewed_at": null,
54+
"nvd_published_at": "2026-09-19T23:17:10Z"
55+
}
56+
}
Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-3mrg-v8x6-xfjw",
4+
"modified": "2026-09-20T00:30:24Z",
5+
"published": "2026-09-20T00:30:24Z",
6+
"aliases": [
7+
"CVE-2026-94057"
8+
],
9+
"details": "Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94057"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://lists.exim.org/lurker/message/20260918.121220.0f87338e.en.html"
25+
}
26+
],
27+
"database_specific": {
28+
"cwe_ids": [
29+
"CWE-93"
30+
],
31+
"severity": "MODERATE",
32+
"github_reviewed": false,
33+
"github_reviewed_at": null,
34+
"nvd_published_at": "2026-09-19T23:17:11Z"
35+
}
36+
}
Lines changed: 72 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,72 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-746c-pwvm-v4p5",
4+
"modified": "2026-09-20T00:30:23Z",
5+
"published": "2026-09-20T00:30:23Z",
6+
"aliases": [
7+
"CVE-2026-93956"
8+
],
9+
"details": "A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Search Engine. Executing a manipulation of the argument Query can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 1.1.3 can resolve this issue. This patch is called 0b2fae333d6b022da7ed4c43e2d41aa03f91dff3. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93956"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/olivier-ls/php-fts/issues/1"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/olivier-ls/php-fts/commit/0b2fae333d6b022da7ed4c43e2d41aa03f91dff3"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/olivier-ls/php-fts"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/olivier-ls/php-fts/tags"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://github.com/sumo166/CVE-apply/blob/main/olivier-ls/PHP-FTS/SearchEngine%20buildHighlights%20Stored%20XSS%20(CWE-79)_cve.md"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://vuldb.com/cve/CVE-2026-93956"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://vuldb.com/submit/943922"
53+
},
54+
{
55+
"type": "WEB",
56+
"url": "https://vuldb.com/vuln/407915"
57+
},
58+
{
59+
"type": "WEB",
60+
"url": "https://vuldb.com/vuln/407915/cti"
61+
}
62+
],
63+
"database_specific": {
64+
"cwe_ids": [
65+
"CWE-79"
66+
],
67+
"severity": "LOW",
68+
"github_reviewed": false,
69+
"github_reviewed_at": null,
70+
"nvd_published_at": "2026-09-19T23:17:09Z"
71+
}
72+
}
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-92v2-hh9v-6vj5",
4+
"modified": "2026-09-20T00:30:24Z",
5+
"published": "2026-09-20T00:30:24Z",
6+
"aliases": [
7+
"CVE-2026-93993"
8+
],
9+
"details": "Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93993"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/mistralai/mistral-vibe/issues/996"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/mistralai/mistral-vibe/commit/c069ffa1e12fb5f2487b489217c40ab97721d553"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/mistralai/mistral-vibe"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/mistralai/mistral-vibe/blob/19b5b74faa78d0816b8d4d4c7d7543fc3520678c/vibe/core/git/repo.py#L411-L431"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://github.com/mistralai/mistral-vibe/releases/tag/v2.25.5"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://www.vulncheck.com/advisories/mistral-vibe-before-2.25.5-remote-code-execution-via-git-post-checkout"
49+
}
50+
],
51+
"database_specific": {
52+
"cwe_ids": [
53+
"CWE-829"
54+
],
55+
"severity": "HIGH",
56+
"github_reviewed": false,
57+
"github_reviewed_at": null,
58+
"nvd_published_at": "2026-09-19T23:17:10Z"
59+
}
60+
}
Lines changed: 64 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,64 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-frhf-rqp4-m3jc",
4+
"modified": "2026-09-20T00:30:23Z",
5+
"published": "2026-09-20T00:30:23Z",
6+
"aliases": [
7+
"CVE-2026-93955"
8+
],
9+
"details": "A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component Download Endpoint. Performing a manipulation of the argument bookId results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. Issue #2431 is closed as completed, but its only comment states that the issue “has already been reported elsewhere.” No fixing commit or pull request is identified there.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93955"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/grimmory-tools/grimmory/issues/2431"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/grimmory-tools/grimmory/issues/2431#issuecomment-5384402858"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/grimmory-tools/grimmory"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://vuldb.com/cve/CVE-2026-93955"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/submit/943921"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://vuldb.com/vuln/407914"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://vuldb.com/vuln/407914/cti"
53+
}
54+
],
55+
"database_specific": {
56+
"cwe_ids": [
57+
"CWE-285"
58+
],
59+
"severity": "LOW",
60+
"github_reviewed": false,
61+
"github_reviewed_at": null,
62+
"nvd_published_at": "2026-09-19T23:17:09Z"
63+
}
64+
}
Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-jpgj-v2p6-hc2c",
4+
"modified": "2026-09-20T00:30:24Z",
5+
"published": "2026-09-20T00:30:24Z",
6+
"aliases": [
7+
"CVE-2026-94055"
8+
],
9+
"details": "Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94055"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://lists.exim.org/lurker/message/20260918.121220.0f87338e.en.html"
25+
}
26+
],
27+
"database_specific": {
28+
"cwe_ids": [
29+
"CWE-416"
30+
],
31+
"severity": "LOW",
32+
"github_reviewed": false,
33+
"github_reviewed_at": null,
34+
"nvd_published_at": "2026-09-19T23:17:10Z"
35+
}
36+
}
Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-pc5q-2x89-w436",
4+
"modified": "2026-09-20T00:30:23Z",
5+
"published": "2026-09-20T00:30:23Z",
6+
"aliases": [
7+
"CVE-2026-93989"
8+
],
9+
"details": "vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent requests, causing different in-flight HTTP requests to return incorrect tokens.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93989"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/vllm-project/vllm/pull/48824"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/vllm-project/vllm"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/vllm-project/vllm/blob/98dff2a81d747d1dba01a47f939f48c3526d4206/vllm/sampling_params.py#L694-L753"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/vllm-project/vllm/blob/98dff2a81d747d1dba01a47f939f48c3526d4206/vllm/v1/worker/gpu/sample/bad_words.py"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://www.vulncheck.com/advisories/vllm-through-0.29.0-cross-request-logits-corruption-via-bad-words"
45+
}
46+
],
47+
"database_specific": {
48+
"cwe_ids": [
49+
"CWE-129"
50+
],
51+
"severity": "LOW",
52+
"github_reviewed": false,
53+
"github_reviewed_at": null,
54+
"nvd_published_at": "2026-09-19T23:17:10Z"
55+
}
56+
}

0 commit comments

Comments
 (0)