MEDIUM6.5CVE-2026-54683NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
MEDIUM5.4Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
MEDIUM6.5Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
MEDIUM6.5Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
MEDIUM4.9Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
CRITICAL9.1Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
CRITICAL9.8Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
MEDIUM6.9Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
MEDIUM4.8Netty: QUIC stateless reset token material exposed through header-visible connection IDs
MEDIUM5.3Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted
MEDIUM6.5GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
MEDIUM5.3netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
MEDIUM6.5In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
MEDIUM5.3Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
MEDIUM6.8Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
MEDIUM4.0Netty: Unix-socket fd receive leaks descriptors when peer sends two at once
MEDIUM6.5epa4all-client: Unauthenticated REST API for Patient Record Writes
CRITICAL9.1Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
CRITICAL9.8Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override
CRITICAL9.1Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
MEDIUM6.5Yamcs has No Rate Limiting on Authentication Endpoint
MEDIUM4.3Yamcs vulnerable to unauthorized user enumeration via IAM API endpoints
MEDIUM4.3Yamcs Vulnerable to LDAP Injection in LdapAuthModule