Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

73 articles
206 topics
RSS Feed
CVE-2026-63072: OpenSSL CMS decrypt writes eight bytes past the unwrap buffer
cveopensslcms

CVE-2026-63072: OpenSSL CMS decrypt writes eight bytes past the unwrap buffer

How to fix CVE-2026-63072: upgrade OpenSSL to 3.0.22, 3.4.7, 3.5.8, 3.6.4, or 4.0.2. CMS_decrypt writes eight bytes past the unwrap buffer. Same 25 August advisory as eight sibling CVEs. Not RCE. FIPS module not in scope.

HOL GuardAug 25, 2026
cveapache hive

CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation

How to fix CVE-2026-53561: upgrade Apache Hive to 4.2.1. Unauthenticated SAML Bearer impersonation in HiveServer2 HTTP. Same 4.2.1 train as Metastore SQLi and Avro SerDe SSRF. Not RCE. Not the Kerberos default.

HOL Guard
Aug 25, 2026
cvevault

CVE-2026-5006: Vault Privilege Escalation via Slash Injection in Templated Policy Paths

How to fix CVE-2026-5006: upgrade HashiCorp Vault Community Edition to 2.0.4 (Enterprise 2.0.4, 1.21.9, 1.20.14, or 1.19.20), then set deny_slash_in_templated_paths = true. Templated policy paths interpolate identity values. A slash in a controlled identity value becomes extra path segments and can grant capabilities the author did not intend. The deny-slash option defaults to false even after upgrade.

HOL Guard
Aug 24, 2026
cvefast uri

CVE-2026-75899: fast-uri SSRF via Repeated Hostname Decoding

How to fix CVE-2026-75899: upgrade fast-uri to 2.4.5, 3.1.6, or 4.1.3. Nested percent-encoding in a hostname becomes localhost after normalize() or resolve(). Not RCE. Same patch train as three sibling High SSRF and host-confusion GHSAs.

HOL Guard
Aug 24, 2026
cvesecurity

CVE-2026-18420: OpenSearch Dashboards TSVB Prototype Pollution RCE

How to fix CVE-2026-18420: upgrade OpenSearch Dashboards to 3.8.0. Authenticated TSVB metrics JSON prototype pollution RCE. Affects OSS and AWS Managed >=3.0.0 <3.8.0.

HOL Guard
Aug 21, 2026
cvesecurity

CVE-2026-19516: Grafana MCP Server SSRF Via Caller-Controlled URL Header

CVE-2026-19516 is a server-side request forgery in the Grafana MCP Server. A caller can set the X-Grafana-URL header to any destination and use the grafana_api_request tool to reach internal services and cloud metadata endpoints. No fix available.

Michael Kantor
Aug 21, 2026
cvesecurity

CVE-2026-77068: n8n Member RCE via MCP Node-Schema Path Traversal

How to fix CVE-2026-77068: upgrade n8n to 2.35.5 (floor 2.33.4 / 2.34.1). Member-level MCP schema path traversal RCE in the MAIN process. Not unauthenticated.

HOL Guard
Aug 20, 2026
cvesecurity

CVE-2026-76832: Agno PythonTools Path Traversal Escapes base_dir

How to fix CVE-2026-76832: upgrade agno to 2.3.24 or later (current PyPI 2.9.0). PythonTools path traversal can read, write, or run files outside base_dir.

HOL Guard
Aug 19, 2026
cvesecurity

BREAKING: CVE-2026-76850 - LMDeploy Pickle RCE in Disaggregated Serving

How to fix CVE-2026-76850: upgrade InternLM lmdeploy to 0.16.0. Unauthenticated pickle RCE in disaggregated serving. Affects >=0.9.2 and <0.16.0.

HOL Guard
Aug 19, 2026
cvesecurity

BREAKING: CVE-2026-18432 - Frontend Admin WordPress Unauthenticated Admin Takeover

CVE-2026-18432 is a CVSS 9.8 privilege-escalation flaw in Frontend Admin by DynamiApps that can let unauthenticated attackers reset the default WordPress administrator account. Update to 3.29.10.

HOL Guard
Aug 16, 2026
cvesecurity

BREAKING: CVE-2026-74764 - Pandora TAR Path Traversal Enables Arbitrary File Write

CVE-2026-74764 is a CVSS 10.0 path traversal in Pandora TAR extraction that lets untrusted archives write outside the analysis directory. v1.12.5 is affected; deploy the upstream fix.

HOL Guard
Aug 16, 2026
cvesecurity

BREAKING: CVE-2026-73043 - SiYuan Template Calculation RCE in Desktop Client

CVE-2026-73043 is a critical SiYuan flaw where unsanitized database Template calculation output reaches Electron innerHTML and can become OS command execution. Upgrade to 3.7.4 or later.

HOL Guard
Aug 16, 2026
cvesecurity

BREAKING: CVE-2026-73046 - SiYuan Basic Auth Lockout Bypass Enables Admin Brute Force

CVE-2026-73046 is a CVSS 9.8 flaw in SiYuan that lets remote attackers bypass CAPTCHA and lockout controls through HTTP Basic Auth and brute-force the admin access code. Upgrade to 3.8.0 or later.

HOL Guard
Aug 16, 2026
1 / 6