#vulnerability β Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vulnerability, aggregated by home.social.
-
π¨ EUVD-2026-88035
π Score: 5.3/10 (CVSS v3.1)
π¦ Product: StarTraining, StarTraining
π’ Vendor: zhistaredu
π Updated: 2026-09-27π A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.isAdmin of the file edu-common/src/main/java/com/edu/common/core/domain/entity/SysUser.java of the component authRole ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88035
-
π¨ EUVD-2026-88034
π Score: 5.3/10 (CVSS v3.1)
π¦ Product: StarTraining, StarTraining
π’ Vendor: zhistaredu
π Updated: 2026-09-27π A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The manipulation results in missing authoriz...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88034
-
π¨ EUVD-2026-88035
π Score: 5.3/10 (CVSS v3.1)
π¦ Product: StarTraining, StarTraining
π’ Vendor: zhistaredu
π Updated: 2026-09-27π A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.isAdmin of the file edu-common/src/main/java/com/edu/common/core/domain/entity/SysUser.java of the component authRole ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88035
-
π¨ EUVD-2026-88034
π Score: 5.3/10 (CVSS v3.1)
π¦ Product: StarTraining, StarTraining
π’ Vendor: zhistaredu
π Updated: 2026-09-27π A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The manipulation results in missing authoriz...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88034
-
π¨ EUVD-2026-88035
π Score: 5.3/10 (CVSS v3.1)
π¦ Product: StarTraining, StarTraining
π’ Vendor: zhistaredu
π Updated: 2026-09-27π A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.isAdmin of the file edu-common/src/main/java/com/edu/common/core/domain/entity/SysUser.java of the component authRole ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88035
-
π¨ EUVD-2026-88034
π Score: 5.3/10 (CVSS v3.1)
π¦ Product: StarTraining, StarTraining
π’ Vendor: zhistaredu
π Updated: 2026-09-27π A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The manipulation results in missing authoriz...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88034
-
π¨ EUVD-2026-88035
π Score: 5.3/10 (CVSS v3.1)
π¦ Product: StarTraining, StarTraining
π’ Vendor: zhistaredu
π Updated: 2026-09-27π A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.isAdmin of the file edu-common/src/main/java/com/edu/common/core/domain/entity/SysUser.java of the component authRole ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88035
-
π¨ EUVD-2026-88034
π Score: 5.3/10 (CVSS v3.1)
π¦ Product: StarTraining, StarTraining
π’ Vendor: zhistaredu
π Updated: 2026-09-27π A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The manipulation results in missing authoriz...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88034
-
π¨ EUVD-2026-88033
π Score: 8.7/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the aut...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88033
-
π¨ EUVD-2026-88032
π Score: 6.9/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry metadata including server names, descriptions, repository URLs, and co...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88032
-
π¨ EUVD-2026-88032
π Score: 6.9/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry metadata including server names, descriptions, repository URLs, and co...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88032
-
π¨ EUVD-2026-88033
π Score: 8.7/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the aut...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88033
-
π¨ EUVD-2026-88032
π Score: 6.9/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry metadata including server names, descriptions, repository URLs, and co...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88032
-
π¨ EUVD-2026-88033
π Score: 8.7/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the aut...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88033
-
π¨ EUVD-2026-88032
π Score: 6.9/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry metadata including server names, descriptions, repository URLs, and co...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88032
-
π¨ EUVD-2026-88033
π Score: 8.7/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the aut...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88033
-
π¨ EUVD-2026-88031
π Score: 8.3/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88031
-
π¨ EUVD-2026-88029
π Score: 9.3/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and man...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88029
-
π¨ EUVD-2026-88031
π Score: 8.3/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88031
-
π¨ EUVD-2026-88029
π Score: 9.3/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and man...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88029
-
π¨ EUVD-2026-88031
π Score: 8.3/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88031
-
π¨ EUVD-2026-88029
π Score: 9.3/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and man...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88029
-
π¨ EUVD-2026-88031
π Score: 8.3/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88031
-
π¨ EUVD-2026-88029
π Score: 9.3/10 (CVSS v3.1)
π¦ Product: obot
π’ Vendor: obot-platform
π Updated: 2026-09-27π obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and man...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88029
-
π¨ EUVD-2026-88030
π Score: 9.3/10 (CVSS v3.1)
π Updated: 2026-09-27π Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapp...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88030
-
π¨ EUVD-2026-88030
π Score: 9.3/10 (CVSS v3.1)
π Updated: 2026-09-27π Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapp...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88030
-
π¨ EUVD-2026-88030
π Score: 9.3/10 (CVSS v3.1)
π Updated: 2026-09-27π Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapp...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88030
-
π¨ EUVD-2026-88030
π Score: 9.3/10 (CVSS v3.1)
π Updated: 2026-09-27π Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapp...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88030
-
π¨ EUVD-2026-88020
π Score: 7.1/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via t...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88020
-
π¨ EUVD-2026-88021
π Score: 7.1/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. Attackers can deliver command execu...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88021
-
π¨ EUVD-2026-88020
π Score: 7.1/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via t...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88020
-
π¨ EUVD-2026-88021
π Score: 7.1/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. Attackers can deliver command execu...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88021
-
π¨ EUVD-2026-88020
π Score: 7.1/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via t...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88020
-
π¨ EUVD-2026-88021
π Score: 7.1/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. Attackers can deliver command execu...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88021
-
π¨ EUVD-2026-88021
π Score: 7.1/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. Attackers can deliver command execu...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88021
-
π¨ EUVD-2026-88020
π Score: 7.1/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via t...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88020
-
π¨ EUVD-2026-88022
π Score: 5.3/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 transition ranges β specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 transl...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88022
-
π¨ EUVD-2026-88023
π Score: 6.0/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for a previously reported nil dereference denial of service (GHSA-qjpp-gffx-2wm9). T...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88023
-
π¨ EUVD-2026-88023
π Score: 6.0/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for a previously reported nil dereference denial of service (GHSA-qjpp-gffx-2wm9). T...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88023
-
π¨ EUVD-2026-88022
π Score: 5.3/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 transition ranges β specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 transl...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88022
-
π¨ EUVD-2026-88022
π Score: 5.3/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 transition ranges β specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 transl...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88022
-
π¨ EUVD-2026-88023
π Score: 6.0/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for a previously reported nil dereference denial of service (GHSA-qjpp-gffx-2wm9). T...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88023
-
π¨ EUVD-2026-88022
π Score: 5.3/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 transition ranges β specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6 transl...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88022
-
π¨ EUVD-2026-88023
π Score: 6.0/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for a previously reported nil dereference denial of service (GHSA-qjpp-gffx-2wm9). T...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88023
-
π¨ EUVD-2026-88025
π Score: 9.3/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88025
-
π¨ EUVD-2026-88024
π Score: 2.3/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract password hashes and perform offline cracking attacks without rat...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88024
-
π¨ EUVD-2026-88024
π Score: 2.3/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract password hashes and perform offline cracking attacks without rat...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88024
-
π¨ EUVD-2026-88025
π Score: 9.3/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88025
-
π¨ EUVD-2026-88024
π Score: 2.3/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract password hashes and perform offline cracking attacks without rat...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88024
-
π¨ EUVD-2026-88025
π Score: 9.3/10 (CVSS v3.1)
π¦ Product: nezha
π’ Vendor: nezhahq
π Updated: 2026-09-27π Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88025