|
cve-2026-59901
|
io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) |
HIGH
|
7.5
|
N/A
|
cvelistv5 |
2026-08-12 |
|
cve-2026-59899
|
io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
HIGH
|
7.5
|
N/A
|
cvelistv5 |
2026-09-01 |
|
cve-2026-59898
|
io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) |
MEDIUM
|
5.3
|
N/A
|
cvelistv5 |
2026-08-06 |
|
cve-2026-59883
|
guzzle/guzzle: Guzzle: Cross-host cookie disclosure and injection due to improper domain matching in CookieJar. |
MEDIUM
|
4.7
|
N/A
|
cvelistv5 |
2026-07-29 |
|
cve-2026-59882
|
guzzlehttp/psr7: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting |
MEDIUM
|
4.2
|
N/A
|
cvelistv5 |
2026-07-10 |
|
cve-2026-58521
|
mediawiki-cargo-extension: Mediawiki - Cargo Extension: SQL Injection vulnerability allows information disclosure and data manipulation. |
HIGH
|
7.3
|
N/A
|
cvelistv5 |
2026-07-01 |
|
cve-2026-58520
|
UrlShortener defaults to ineffective validation open to third-party redirects |
MEDIUM
|
6.9
|
N/A
|
cvelistv5 |
2026-07-01 |
|
cve-2026-58517
|
wikilambda: WikiLambda Extension: Authentication bypass due to improper input neutralization |
CRITICAL
|
9.1
|
N/A
|
cvelistv5 |
2026-07-02 |
|
cve-2026-58038
|
timeline: EasyTimeline: Wikimedia Foundation Timeline: Cross-site Scripting vulnerability |
LOW
|
3.7
|
N/A
|
cvelistv5 |
2026-07-03 |
|
cve-2026-58037
|
Core log entries for exceptions and XSS issues in log entry formatting code that may be caused by user-controlled input |
NONE
|
N/A
|
N/A
|
cvelistv5 |
2026-07-01 |
|
cve-2026-58033
|
"Total number of distinct authors" statistic at action=info does not exclude revisions where the author name was deleted |
MEDIUM
|
5.3
|
N/A
|
cvelistv5 |
2026-07-01 |
|
cve-2026-58032
|
mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html |
MEDIUM
|
5.3
|
N/A
|
cvelistv5 |
2026-07-01 |
|
cve-2026-58030
|
SyntaxHighlight stored XSS via unsanitized 'linelinks' attribute |
MEDIUM
|
5.3
|
N/A
|
cvelistv5 |
2026-07-01 |
|
cve-2026-58029
|
Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata |
MEDIUM
|
5.3
|
N/A
|
cvelistv5 |
2026-07-01 |
|
cve-2026-58028
|
Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets |
NONE
|
N/A
|
N/A
|
cvelistv5 |
2026-07-01 |
|
cve-2026-58027
|
QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UI |
MEDIUM
|
5.3
|
N/A
|
cvelistv5 |
2026-07-01 |
|
cve-2026-58026
|
$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces |
NONE
|
N/A
|
N/A
|
cvelistv5 |
2026-07-01 |
|
cve-2026-58025
|
Remote Code Execution via Unsafe Deserialization in LogItem Import |
MEDIUM
|
5.9
|
N/A
|
cvelistv5 |
2026-07-01 |
|
cve-2026-58024
|
API identification of users on private wikis |
MEDIUM
|
5.1
|
N/A
|
cvelistv5 |
2026-07-01 |
|
cve-2026-57221
|
RabbitMQ: RabbitMQ: Information disclosure via authorization bypass in AMQP 0-9-1 operations |
MEDIUM
|
5.0
|
N/A
|
cvelistv5 |
2026-07-29 |
|
cve-2026-57220
|
rabbitmq-server: RabbitMQ: Denial of Service via oversized stream frames |
HIGH
|
7.5
|
N/A
|
cvelistv5 |
2026-07-29 |
|
cve-2026-57219
|
RabbitMQ: RabbitMQ: OAuth 2 client secret disclosure via obsolete API endpoint |
HIGH
|
7.5
|
N/A
|
cvelistv5 |
2026-07-29 |
|
cve-2026-57218
|
rabbitmq-server: RabbitMQ: Information disclosure due to improper consumer reauthorization |
MEDIUM
|
6.5
|
N/A
|
cvelistv5 |
2026-07-29 |
|
cve-2026-57217
|
rabbitmq: RabbitMQ: Authorization bypass allows unauthorized topic writes and binds during metadata-store failures |
MEDIUM
|
6.5
|
N/A
|
cvelistv5 |
2026-07-29 |
|
cve-2026-57216
|
SUSE CVE CVE-2026-57216 |
UNKNOWN
|
N/A
|
N/A
|
cvelistv5 |
2026-07-15 |
|
cve-2026-57215
|
RabbitMQ: RabbitMQ: Persistent foreign bindings allow unauthorized message routing |
HIGH
|
8.1
|
N/A
|
cvelistv5 |
2026-07-29 |
|
cve-2026-57214
|
RabbitMQ: RabbitMQ: Cross-site Scripting in management UI allows arbitrary JavaScript execution |
MEDIUM
|
5.4
|
N/A
|
cvelistv5 |
2026-08-08 |
|
cve-2026-57213
|
rabbitmq-server: RabbitMQ: Information Disclosure via Cross-Site Scripting in Federation Management |
MEDIUM
|
5.2
|
N/A
|
cvelistv5 |
2026-07-29 |
|
cve-2026-57212
|
rabbitmq-server: RabbitMQ: Denial of Service via oversized JSON bodies in HTTP API |
HIGH
|
7.7
|
N/A
|
cvelistv5 |
2026-07-29 |
|
cve-2026-57211
|
rabbitmq: RabbitMQ: Information disclosure via path validation bypass in management plugin |
CRITICAL
|
10.0
|
N/A
|
cvelistv5 |
2026-07-29 |