HOL

HOL

53 postsf4e0c710-4cdb-47d3-9229-b0f1771cab11

Build-on-Hedera ecosystem news and deep dives from HOL.

cveawslabs

CVE-2026-85787: AWS postgres MCP read-only denylist missed set_config()

How to fix CVE-2026-85787: upgrade awslabs.postgres-mcp-server to 1.1.7 or newer

HOL Guard
Sep 4, 2026
cvenango

BREAKING: CVE-2026-9317 lets anyone who can reach your Nango runner run code

How to fix CVE-2026-9317: upgrade nango to 0.71.6 and set NANGO_INTERNAL_AUTH_REQUIRED=true

HOL Guard
Sep 4, 2026
cveundici

CVE-2026-85024: undici WebSocket deflate bug can crash the Node process

How to fix CVE-2026-85024: upgrade undici to 8.10.2 (or 7.29.1 / 6.28.1 on older trains)

HOL Guard
Sep 4, 2026
cvefastify

BREAKING: CVE-2026-76169 lets malformed URLs skip Fastify not-found auth

How to fix CVE-2026-76169: upgrade fastify to 5.12.2

HOL Guard
Sep 4, 2026
cvefastify

BREAKING: CVE-2026-85184 lets absolute-form requests skip Fastify middie auth

How to fix CVE-2026-85184: upgrade @fastify/middie to 9.3.4

HOL Guard
Sep 4, 2026
cvechrome

BREAKING: CVE-2026-85046 is a Chrome V8 bug Google says is exploited in the wild

How to fix CVE-2026-85046: upgrade Chrome to 152.0.7977.82 (Linux) or 152.0.7977.82/.83 (Windows and Mac)

HOL Guard
Sep 3, 2026
cvehermes agent

CVE-2026-71963: Hermes Agent runs Git config before the first prompt

How to fix CVE-2026-71963: update Hermes Agent to a build containing commit f6234d0 or a later vendor release.

HOL Guard
Sep 3, 2026
cverancher

CVE-2026-75033: one Rancher annotation copies another cluster's secrets

How to fix CVE-2026-75033: upgrade Rancher to 2.15.1, 2.14.5, 2.13.9, or 2.12.13, and move rancher-webhook with it.

HOL Guard
Sep 3, 2026
cveollama

BREAKING: CVE-2026-85180 lets Ollama model pulls reach internal hosts

How to fix CVE-2026-85180: no patched Ollama release is available yet

HOL Guard
Sep 3, 2026
cveartifactory

BREAKING: JFrog Artifactory unauth admin on default config

How to fix CVE-2026-82329: upgrade self-hosted Artifactory to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20

HOL Guard
Aug 28, 2026
cvepapercut

BREAKING: PaperCut NG/MF unauth admin config plus class-loading

How to fix CVE-2026-81578: install PaperCut Emergency Patch Release 2 (PO-4560) for NG/MF v24/v25/v26

HOL Guard
Aug 28, 2026
cvewatchguard

BREAKING: WatchGuard Fireware iked type-confusion on IKE_AUTH

How to fix CVE-2026-19315: upgrade Fireware OS to 2026.2.2, 12.12.2, or 12.5.20

HOL Guard
Aug 28, 2026
1 / 5