Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

88 articles
244 topics
RSS Feed
CVE-2026-85024: undici WebSocket deflate bug can crash the Node process
cveundicinodejs

CVE-2026-85024: undici WebSocket deflate bug can crash the Node process

How to fix CVE-2026-85024: upgrade undici to 8.10.2 (or 7.29.1 / 6.28.1 on older trains)

HOL GuardSep 4, 2026
cvefastify

BREAKING: CVE-2026-76169 lets malformed URLs skip Fastify not-found auth

How to fix CVE-2026-76169: upgrade fastify to 5.12.2

HOL Guard
Sep 4, 2026
cvefastify

BREAKING: CVE-2026-85184 lets absolute-form requests skip Fastify middie auth

How to fix CVE-2026-85184: upgrade @fastify/middie to 9.3.4

HOL Guard
Sep 4, 2026
cvechrome

BREAKING: CVE-2026-85046 is a Chrome V8 bug Google says is exploited in the wild

How to fix CVE-2026-85046: upgrade Chrome to 152.0.7977.82 (Linux) or 152.0.7977.82/.83 (Windows and Mac)

HOL Guard
Sep 3, 2026
cvehermes agent

CVE-2026-71963: Hermes Agent runs Git config before the first prompt

How to fix CVE-2026-71963: update Hermes Agent to a build containing commit f6234d0 or a later vendor release.

HOL Guard
Sep 3, 2026
cverancher

CVE-2026-75033: one Rancher annotation copies another cluster's secrets

How to fix CVE-2026-75033: upgrade Rancher to 2.15.1, 2.14.5, 2.13.9, or 2.12.13, and move rancher-webhook with it.

HOL Guard
Sep 3, 2026
cveollama

BREAKING: CVE-2026-85180 lets Ollama model pulls reach internal hosts

How to fix CVE-2026-85180: no patched Ollama release is available yet

HOL Guard
Sep 3, 2026
cveartifactory

BREAKING: JFrog Artifactory unauth admin on default config

How to fix CVE-2026-82329: upgrade self-hosted Artifactory to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20

HOL Guard
Aug 28, 2026
cvepapercut

BREAKING: PaperCut NG/MF unauth admin config plus class-loading

How to fix CVE-2026-81578: install PaperCut Emergency Patch Release 2 (PO-4560) for NG/MF v24/v25/v26

HOL Guard
Aug 28, 2026
cvewatchguard

BREAKING: WatchGuard Fireware iked type-confusion on IKE_AUTH

How to fix CVE-2026-19315: upgrade Fireware OS to 2026.2.2, 12.12.2, or 12.5.20

HOL Guard
Aug 28, 2026
cveredis

CVE-2026-81934: Redis TLS pending-list use-after-free (public RCE PoC)

How to fix CVE-2026-81934: upgrade Redis to 8.2.9, 8.4.6, 8.6.6, 8.8.2, or 8.10.1

HOL Guard
Aug 27, 2026
cveteamviewer

CVE-2026-19042: TeamViewer Linux Chat Link Command Injection (and Sibling CVE-2026-16444)

How to fix CVE-2026-19042: upgrade TeamViewer Full Client and Host for Linux to 15.81

HOL Guard
Aug 26, 2026
cvechainlit

CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)

How to fix CVE-2026-45018: upgrade chainlit to 2.12.0, then restart so /mcp loads the new wheel

HOL Guard
Aug 25, 2026
1 / 8