Vulnerabilities and CVEs Stoat CVE-2026-73057–73059: image proxy SSRF and DoS meet a history-permission bypass
Three Stoat CVEs combine a missing IPv6 address, unbounded SVG rendering and inconsistent message permissions. We explain the 0.15.0 fix.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Vulnerabilities and CVEs Three Stoat CVEs combine a missing IPv6 address, unbounded SVG rendering and inconsistent message permissions. We explain the 0.15.0 fix.
Vulnerabilities and CVEs Unbounded CSP reports and request-driven locale caches can exhaust the Java heap. We analyse S2-073, S2-074, mitigations and fixed releases.
Identity and Access An option-merging error makes @fastify/jwt ignore a route-specific key. We explain the authorization bypass, affected architectures and upgrade to 10.2.2.
Cloud, Infrastructure and DevSecOps TAR path traversal enables arbitrary file writes while a DAA decompression bomb exhausts the analyser. We explain the fixes in Pandora 1.12.6.
Vulnerabilities and CVEs PDF annotations, calculations and database metadata reach innerHTML while Node Integration raises impact to code execution. We analyse the CVE wave and v3.7.4.
Cloud, Infrastructure and DevSecOps The Net Check feature accepts Socket.io input and executes it as root. We explain the OT risk, the 3.50.1.19 update and effective segmentation.
Vulnerabilities and CVEs Unauthenticated SQL injection in DataONE CN endpoints exposes data and enables database changes. We cover the 3.4.1 upgrade and a safe workaround.
AI Security An open API, permissive CORS and a scratchpad calling exec() form a complete RCE chain. We explain Minds Platform exposure and response without a patch.
Vulnerabilities and CVEs First- and second-order flaws in backlink search can compromise the SiYuan database. We examine the mechanism, exposure and upgrade to 3.7.4.
Supply Chain Security CVE-2026-73623–73625 bypass option controls through templates, diff output and kwarg value smuggling. We examine the fixes and CI exposure.
AI Security Missing file_path validation in confluence_upload_attachment exposes every server-readable file. Prompt injection can activate the vulnerable flow.
Vulnerabilities and CVEs PostgreSQL 18.6, 17.11, 16.15, 15.19 and 14.24 address 28 vulnerabilities. We map the highest-risk classes and a safe update plan.
Supply Chain Security OIDC client flaws allowed discovery redirects, verifier-cache poisoning and ServiceAccount token disclosure. Fulcio 1.8.6 fixes all three paths.
Supply Chain Security The archived cloudflare/pages-action is vulnerable in every release and will not be patched. Migration to wrangler-action also requires tighter tokens.
Vulnerabilities and CVEs An authentication flaw allows remote GUI or CLI access without a valid account. We map affected branches, immediate controls and investigation steps.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.