#patchstack — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #patchstack, aggregated by home.social.
-
🔴 CVE-2026-49457 - Critical (9.1)
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49457/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-49457 - Critical (9.1)
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49457/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-45699 - High (7.5)
Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the copydir() function of Netatalk's afpd daemon due to an integer underflow in the ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-45699 - High (7.5)
Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the copydir() function of Netatalk's afpd daemon due to an integer underflow in the ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-73678 - Critical (10)
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73678/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-73678 - Critical (10)
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73678/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19845 - High (8.8)
A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-bas...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19845/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19845 - High (8.8)
A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-bas...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19845/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19844 - High (8.8)
A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19844/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19844 - High (8.8)
A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19844/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-46439 - High (7.8)
compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46439/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-46439 - High (7.8)
compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46439/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-53970 - High (7.5)
ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53970/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-53970 - High (7.5)
ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53970/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-63700 - High (7.8)
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63700/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-63700 - High (7.8)
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63700/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19768 - High (8.1)
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19768 - High (8.1)
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73633 - High (7.5)
Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73633/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73633 - High (7.5)
Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73633/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-69101 - High (7.7)
Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditW...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69101/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-69101 - High (7.7)
Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditW...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69101/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-72859 - High (7.7)
Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by sending POST requests to the attachments endpoint. The route was chang...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72859/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-72859 - High (7.7)
Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by sending POST requests to the attachments endpoint. The route was chang...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72859/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-72837 - High (8.8)
File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72837/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-72837 - High (8.8)
File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72837/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-72836 - High (8.1)
FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72836/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-72836 - High (8.1)
FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72836/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19821 - High (8.8)
A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argum...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19821/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19821 - High (8.8)
A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argum...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19821/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-12949 - Critical (9.8)
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie onl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12949/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-12949 - Critical (9.8)
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie onl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12949/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19814 - High (8.8)
A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based bu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19814/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19814 - High (8.8)
A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based bu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19814/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19815 - High (8.8)
A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19815/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19815 - High (8.8)
A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19815/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19811 - High (8.8)
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in sta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19811/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19811 - High (8.8)
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in sta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19811/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19813 - High (8.8)
A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19813/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19813 - High (8.8)
A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19813/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19812 - High (8.8)
A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer ov...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19812/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19812 - High (8.8)
A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer ov...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19812/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-72850 - Critical (9.1)
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the tempo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72850/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-72850 - Critical (9.1)
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the tempo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72850/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-72849 - High (7.7)
Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POS...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72849/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-72849 - High (7.7)
Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POS...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72849/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73408 - High (7.6)
Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table with a bac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73408/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73408 - High (7.6)
Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table with a bac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73408/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73305 - High (8.8)
Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleValidation.ts....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73305/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73305 - High (8.8)
Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleValidation.ts....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73305/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-72857 - High (7.7)
Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72857/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-72857 - High (7.7)
Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-72857/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73659 - High (8.1)
Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.$.ts pass a caller-controlled filename through resolveStoreProtocolForPacke...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73659/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73659 - High (8.1)
Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.$.ts pass a caller-controlled filename through resolveStoreProtocolForPacke...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73659/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73658 - High (8.2)
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-control...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73658/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73658 - High (8.2)
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-control...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73658/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73841 - High (8.8)
OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view usin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73841/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73841 - High (8.8)
OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view usin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73841/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73667 - High (8.8)
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workflow parame...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73667/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-73667 - High (8.8)
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workflow parame...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73667/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack