1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 1:35 AM 16,370 active 1,443 known exploited

Catalog summary

16,370

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 1:35 AM 16,370 active 1,443 known exploited

Catalog summary

16,370

Active CVEs

8,461

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,401–4,450 of 16,370 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-59938Medium
    pypdf: Possible large memory usage for wrong image dimensions
    CVSS 6.9
    py-pdf/pypdfgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  2. CVE-2026-14362Medium
    Denial of service via crafted push/pull gossip message in memberlist
    CVSS 4.9
    HashiCorp/Shared librarygeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  3. CVE-2026-59731High
    Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
    CVSS 8.2
    withastro/astrogeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  4. CVE-2026-59927Medium
    Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files
    CVSS 5.3
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  5. CVE-2026-59928High
    Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
    CVSS 7.5
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  6. CVE-2026-59924Medium
    Mistune: Arbitrary File Read via Include directive path traversal
    CVSS 5.9
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  7. CVE-2026-59929Medium
    Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
    CVSS 6.1
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  8. CVE-2025-3110High
    CISA ADP Vulnrichment
    CVSS 7.5
    OpenVPN/Access Servergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  9. CVE-2026-59925High
    inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
    CVSS 7.5
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  10. CVE-2026-59926Medium
    Mistune: XSS via unescaped class option in Admonition directive
    CVSS 5.3
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  11. CVE-2026-29009High
    U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK
    CVSS 8.2
    u-boot/u-bootgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 24, 2026 Fix availableView HOL analysis
  12. CVE-2026-29008High
    U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()
    CVSS 7.5
    u-boot/u-bootgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 14, 2026View HOL analysis
  13. CVE-2026-59923Medium
    Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
    CVSS 6.1
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  14. CVE-2026-59930Medium
    Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
    CVSS 4.3
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  15. CVE-2026-59922High
    Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
    CVSS 7.5
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  16. CVE-2026-29007Medium
    U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c
    CVSS 5.3
    u-boot/u-bootgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 14, 2026View HOL analysis
  17. CVE-2026-59895Medium
    Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
    CVSS 6.1
    hono, honojs/honogeneric · npm
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 23, 2026 Fix availableView HOL analysis
  18. CVE-2026-59896Medium
    hono/jsx does not isolate context per request, leading to cross-request data disclosure
    CVSS 6.5
    honojs/honogeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  19. CVE-2026-59897Medium
    Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
    CVSS 4.8
    hono, honojs/honogeneric · npm
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 23, 2026 Fix availableView HOL analysis
  20. CVE-2026-59892High
    OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
    CVSS 7.5
    @opentelemetry/propagator-jaeger, open-telemetry/opentelemetry-jsgeneric · npm
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 24, 2026 Fix availableView HOL analysis
  21. CVE-2026-59890Medium
    setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
    CVSS 6.1
    pypa/setuptools, setuptoolsgeneric · pypi
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 23, 2026 Fix availableView HOL analysis
  22. CVE-2026-59887High
    linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
    CVSS 7.5
    markdown-it/linkify-itgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  23. CVE-2026-59883Medium
    Guzzle: Cookie Disclosure and Injection via IP-Address Domains
    CVSS 4.7
    guzzle/guzzlegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-59882Medium
    guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
    CVSS 4.2
    guzzle/psr7generic
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  25. CVE-2026-59879High
    Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
    CVSS 8.7
    immutable, immutable-js/immutable-jsgeneric · npm
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 23, 2026 Fix availableView HOL analysis
  26. CVE-2026-42505Medium
    Invoking Encrypted Client Hello privacy leak in crypto/tls
    CVSS 5.3
    Go standard library/crypto/tlsgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  27. CVE-2026-39822High
    Root escape via symlink plus trailing slash in os
    CVSS 7.8
    Go standard library/osgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  28. CVE-2026-59880High
    Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
    CVSS 8.7
    immutable, immutable-js/immutable-jsgeneric · npm
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 23, 2026 Fix availableView HOL analysis
  29. CVE-2026-59725High
    Socket.IO: Engine.IO Polling Transport Connection Exhaustion
    CVSS 7.5
    socketio/socket.iogeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-59724High
    Socket.IO: Engine.IO WebTransport SID DoS
    CVSS 7.5
    socketio/socket.iogeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-59876Medium
    protobufjs: Text Format string map parsing can mutate returned map object prototype
    CVSS 4.8
    protobufjs/protobuf.jsgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  32. CVE-2026-59877Medium
    protobufjs: Denial of Service via infinite loop in .proto option parsing
    CVSS 5.3
    protobufjs/protobuf.jsgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  33. CVE-2026-53951High
    Copier: trust-prefix bypass via path traversal runs tasks unprompted
    CVSS 8.8
    copier-org/copiergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  34. CVE-2026-59871Medium
    node-tar: Process crash via PAX numeric path type confusion
    CVSS 5.3
    isaacs/node-targeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  35. CVE-2026-9074Critical
    IBM API Connect SQL Injection
    CVSS 9.1
    IBM/API Connectgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  36. CVE-2026-59874High
    node-tar: Negative tar entry size causes infinite loop in archive replace
    CVSS 8.7
    isaacs/node-targeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  37. CVE-2026-59873Critical
    node-tar: Decompression/parse DoS via unlimited input
    CVSS 9.2
    isaacs/node-targeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  38. CVE-2026-3144High
    IBM API Connect Default Credentials
    CVSS 8.1
    IBM/API Connectgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  39. CVE-2026-59875Medium
    node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
    CVSS 5.3
    isaacs/node-targeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  40. CVE-2026-59868Medium
    js-yaml: YAML merge-key chains can force quadratic CPU consumption
    CVSS 5.3
    nodeca/js-yamlgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  41. CVE-2026-59869High
    js-yaml: YAML merge-key chains can force quadratic CPU consumption
    CVSS 7.5
    nodeca/js-yamlgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  42. CVE-2026-59870Medium
    js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing
    CVSS 5.3
    nodeca/js-yamlgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-54344Medium
    ToolJet GitHub Actions comment body shell injection exposes deployment secrets
    CVSS 4.7
    ToolJet/ToolJetgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  44. CVE-2026-55761High
    Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances
    CVSS 7.1
    portainer/portainergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  45. CVE-2026-14967Low
    Path traversal in github_workflows allows writing artifacts outside output directory
    CVSS 3.1
    Black Lantern Security/BBOTgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  46. CVE-2026-14966Low
    Symlink guard bypass in unarchive module allows planting symlinks during extraction
    CVSS 3.1
    Black Lantern Security/BBOTgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  47. CVE-2026-57439Medium
    CyberChef: Prototype pollution in Series Chart operation
    CVSS 5.0
    gchq/CyberChefgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2026-15063Medium
    Trustyai-service-operator: trustyai service operator: gorch port bypass when auth is enabled
    CVSS 6.3
    Affected software not mappedEcosystem not listed
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  49. CVE-2026-49147High
    App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes
    CVSS 7.5
    PETDANCE/App::Ackgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  50. CVE-2026-49146High
    App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc
    CVSS 7.5
    PETDANCE/App::Ackgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
Page 89 of 328
Previous8788899091Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,461

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 4,401–4,450 of 16,370 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-59938Medium
    pypdf: Possible large memory usage for wrong image dimensions
    CVSS 6.9
    py-pdf/pypdfgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  2. CVE-2026-14362Medium
    Denial of service via crafted push/pull gossip message in memberlist
    CVSS 4.9
    HashiCorp/Shared librarygeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026 Fix availableView HOL analysis
  3. CVE-2026-59731High
    Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
    CVSS 8.2
    withastro/astrogeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  4. CVE-2026-59927Medium
    Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files
    CVSS 5.3
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  5. CVE-2026-59928High
    Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
    CVSS 7.5
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  6. CVE-2026-59924Medium
    Mistune: Arbitrary File Read via Include directive path traversal
    CVSS 5.9
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  7. CVE-2026-59929Medium
    Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
    CVSS 6.1
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  8. CVE-2025-3110High
    CISA ADP Vulnrichment
    CVSS 7.5
    OpenVPN/Access Servergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  9. CVE-2026-59925High
    inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
    CVSS 7.5
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  10. CVE-2026-59926Medium
    Mistune: XSS via unescaped class option in Admonition directive
    CVSS 5.3
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  11. CVE-2026-29009High
    U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK
    CVSS 8.2
    u-boot/u-bootgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 24, 2026 Fix availableView HOL analysis
  12. CVE-2026-29008High
    U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()
    CVSS 7.5
    u-boot/u-bootgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 14, 2026View HOL analysis
  13. CVE-2026-59923Medium
    Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
    CVSS 6.1
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  14. CVE-2026-59930Medium
    Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
    CVSS 4.3
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  15. CVE-2026-59922High
    Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
    CVSS 7.5
    lepture/mistunegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  16. CVE-2026-29007Medium
    U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c
    CVSS 5.3
    u-boot/u-bootgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 14, 2026View HOL analysis
  17. CVE-2026-59895Medium
    Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
    CVSS 6.1
    hono, honojs/honogeneric · npm
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 23, 2026 Fix availableView HOL analysis
  18. CVE-2026-59896Medium
    hono/jsx does not isolate context per request, leading to cross-request data disclosure
    CVSS 6.5
    honojs/honogeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  19. CVE-2026-59897Medium
    Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
    CVSS 4.8
    hono, honojs/honogeneric · npm
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 23, 2026 Fix availableView HOL analysis
  20. CVE-2026-59892High
    OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
    CVSS 7.5
    @opentelemetry/propagator-jaeger, open-telemetry/opentelemetry-jsgeneric · npm
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 24, 2026 Fix availableView HOL analysis
  21. CVE-2026-59890Medium
    setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
    CVSS 6.1
    pypa/setuptools, setuptoolsgeneric · pypi
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 23, 2026 Fix availableView HOL analysis
  22. CVE-2026-59887High
    linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
    CVSS 7.5
    markdown-it/linkify-itgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  23. CVE-2026-59883Medium
    Guzzle: Cookie Disclosure and Injection via IP-Address Domains
    CVSS 4.7
    guzzle/guzzlegeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  24. CVE-2026-59882Medium
    guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
    CVSS 4.2
    guzzle/psr7generic
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  25. CVE-2026-59879High
    Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
    CVSS 8.7
    immutable, immutable-js/immutable-jsgeneric · npm
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 23, 2026 Fix availableView HOL analysis
  26. CVE-2026-42505Medium
    Invoking Encrypted Client Hello privacy leak in crypto/tls
    CVSS 5.3
    Go standard library/crypto/tlsgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  27. CVE-2026-39822High
    Root escape via symlink plus trailing slash in os
    CVSS 7.8
    Go standard library/osgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026 Fix availableView HOL analysis
  28. CVE-2026-59880High
    Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
    CVSS 8.7
    immutable, immutable-js/immutable-jsgeneric · npm
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 23, 2026 Fix availableView HOL analysis
  29. CVE-2026-59725High
    Socket.IO: Engine.IO Polling Transport Connection Exhaustion
    CVSS 7.5
    socketio/socket.iogeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  30. CVE-2026-59724High
    Socket.IO: Engine.IO WebTransport SID DoS
    CVSS 7.5
    socketio/socket.iogeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  31. CVE-2026-59876Medium
    protobufjs: Text Format string map parsing can mutate returned map object prototype
    CVSS 4.8
    protobufjs/protobuf.jsgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  32. CVE-2026-59877Medium
    protobufjs: Denial of Service via infinite loop in .proto option parsing
    CVSS 5.3
    protobufjs/protobuf.jsgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  33. CVE-2026-53951High
    Copier: trust-prefix bypass via path traversal runs tasks unprompted
    CVSS 8.8
    copier-org/copiergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  34. CVE-2026-59871Medium
    node-tar: Process crash via PAX numeric path type confusion
    CVSS 5.3
    isaacs/node-targeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  35. CVE-2026-9074Critical
    IBM API Connect SQL Injection
    CVSS 9.1
    IBM/API Connectgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  36. CVE-2026-59874High
    node-tar: Negative tar entry size causes infinite loop in archive replace
    CVSS 8.7
    isaacs/node-targeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  37. CVE-2026-59873Critical
    node-tar: Decompression/parse DoS via unlimited input
    CVSS 9.2
    isaacs/node-targeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  38. CVE-2026-3144High
    IBM API Connect Default Credentials
    CVSS 8.1
    IBM/API Connectgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026 Fix availableView HOL analysis
  39. CVE-2026-59875Medium
    node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
    CVSS 5.3
    isaacs/node-targeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  40. CVE-2026-59868Medium
    js-yaml: YAML merge-key chains can force quadratic CPU consumption
    CVSS 5.3
    nodeca/js-yamlgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  41. CVE-2026-59869High
    js-yaml: YAML merge-key chains can force quadratic CPU consumption
    CVSS 7.5
    nodeca/js-yamlgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 13, 2026View HOL analysis
  42. CVE-2026-59870Medium
    js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing
    CVSS 5.3
    nodeca/js-yamlgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  43. CVE-2026-54344Medium
    ToolJet GitHub Actions comment body shell injection exposes deployment secrets
    CVSS 4.7
    ToolJet/ToolJetgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  44. CVE-2026-55761High
    Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances
    CVSS 7.1
    portainer/portainergeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  45. CVE-2026-14967Low
    Path traversal in github_workflows allows writing artifacts outside output directory
    CVSS 3.1
    Black Lantern Security/BBOTgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  46. CVE-2026-14966Low
    Symlink guard bypass in unarchive module allows planting symlinks during extraction
    CVSS 3.1
    Black Lantern Security/BBOTgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  47. CVE-2026-57439Medium
    CyberChef: Prototype pollution in Series Chart operation
    CVSS 5.0
    gchq/CyberChefgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 10, 2026View HOL analysis
  48. CVE-2026-15063Medium
    Trustyai-service-operator: trustyai service operator: gorch port bypass when auth is enabled
    CVSS 6.3
    Affected software not mappedEcosystem not listed
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 9, 2026View HOL analysis
  49. CVE-2026-49147High
    App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes
    CVSS 7.5
    PETDANCE/App::Ackgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026View HOL analysis
  50. CVE-2026-49146High
    App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc
    CVSS 7.5
    PETDANCE/App::Ackgeneric
    PublishedJul 8, 2026First seen at HOL Jul 8, 2026Updated Jul 8, 2026 Fix availableView HOL analysis
Page 89 of 328
Previous8788899091Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard