AISLE CVE Discoveries
CVEs our AI-native engine discovered in the world's most audited code, responsibly disclosed to maintainers.
CVE-2025-64756
node-globCommand injection via shell metacharacters in filenames with the CLI -c/--cmd option
CVE-2025-59464
nodeMemory leak converting X.509 certificate fields in socket.getPeerCertificate(true)
CVE-2025-55753
Apache HTTP ServerInteger overflow in the mod_md ACME renewal backoff leading to delay-free retries
CVE-2025-13502
WebKitGTKOut-of-bounds read and integer underflow in the GLib remote inspector server
CVE-2025-13016
FirefoxIncorrect boundary conditions in the JavaScript WebAssembly component
CVE-2025-9230
OpenSSLOut-of-bounds read and write in RFC 3211 KEK unwrap when decrypting CMS messages
CVE-2026-32144
OTPOCSP designated-responder authorization bypass via missing signature verification
CVE-2026-9547
curlKnown-host key type mismatch silently accepted via the CURLOPT_SSH_KEYFUNCTION callback
CVE-2026-3833
GnuTLSName constraints bypass via case-sensitive dNSName and rfc822Name comparison
CVE-2025-69419
OpenSSLOut-of-bounds write in PKCS12_get_friendlyname() UTF-8 conversion
CVE-2026-71226
libkcapiMemory corruption from uncanceled AIO requests in the one-shot AIO error path
CVE-2026-47687
FOGStored XSS in the Inventory Report via unescaped option labels in selectForm()
CVE-2026-47685
FOGStored XSS in the Host Management page via the unauthenticated inventory endpoint
CVE-2026-29168
Apache HTTP ServerUnbounded resource allocation in mod_md when processing OCSP response data
CVE-2026-28448
OpenClawallowFrom allowlist bypass in the Twitch plugin when allowedRoles is empty
CVE-2026-9080
curlUse-after-free when curl_easy_pause() is called from the socket callback
CVE-2026-75147
FFmpegFFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c
CVE-2026-72694
mrtgSymlink-following chown allows local privilege escalation via pid file path manipulation
CVE-2026-67419
RabbitMQConsecutive topic wildcards cause combinatorial routing work
CVE-2026-65050
Ninja FormsMissing authorization in the submissions-table block exposes form submissions to visitors
CVE-2026-64833
FFmpegOut-of-bounds read in the S/PDIF muxer via an oversized DTS core_size value
CVE-2026-48613
phpBBSQL injection during profile field migration via user-supplied profile field data
CVE-2026-25927
openemrIDOR in the DICOM viewer state API allows reading or modifying any document's state
CVE-2026-25147
openemrIDOR in the portal payment page via a user-supplied pid parameter
CVE-2026-24902
TrustTunnelSSRF and private network restriction bypass via numeric IP destinations
CVE-2026-22695
libpngHeap buffer over-read in png_image_finish_read when reading interlaced 16-bit PNGs
CVE-2026-9808
mautic/coreOwner-scope role restrictions not enforced on API v2 endpoints, exposing other users' data
CVE-2025-39840
LinuxOut-of-bounds read in audit_compare_dname_path() when watching the root directory
CVE-2025-39839
LinuxOut-of-bounds read and write in batman-adv network-coding decode
CVE-2026-56109
alsa-libDouble free in parse_def() when parsing nested compound configuration blocks
CVE-2026-44604
rpmCommand injection in rpmuncompress via an archive's top-level directory name
CVE-2026-67217
cJSONNon-atomic JSON Patch application destroys target document members on failed operations
CVE-2026-65051
Ninja FormsValidation bypass via client-controlled field metadata in the AJAX submission handler
CVE-2025-65092
esp-idfOut-of-bounds read when parsing JPEG headers for the ESP32-P4 hardware decoder
CVE-2026-28450
OpenClawMissing authentication on the Nostr plugin's profile HTTP endpoints
CVE-2026-23893
opencryptokiSymlink following in group-writable token directories leading to privilege escalation
CVE-2025-41117
grafana/grafanaXSS via stack traces rendered as raw HTML in the Explore Traces view
CVE-2026-73583
sblim-sfcbUnsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr
CVE-2026-22791
opencryptokiHeap buffer overflow in C_WrapKey with CKM_ECDH_AES_KEY_WRAP via compressed EC keys
CVE-2026-19696
WiresharkOut-of-bounds write in BLF file parsing
CVE-2026-73199
freeipaNull pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value
CVE-2026-71225
libkcapiIV reuse across chunks in one-shot symmetric cipher operations on large inputs
CVE-2026-70368
stunnelStack out-of-bounds read in s_vlog() when handling oversized log messages
CVE-2026-55894
CapstoneOut-of-bounds read in sh_disassemble when disassembling crafted SH2A bytecode
CVE-2026-55893
CapstoneHeap buffer overflow in set_reg_n when disassembling crafted SH2A FPU bytecode
CVE-2026-53583
libgit2Inverted IP SubjectAltName comparison in the OpenSSL backend skips authenticity checks
CVE-2026-48744
saleor/saleorPermission check bypass in channelUpdate via all([]) lets anonymous users modify channels
CVE-2026-47729
squidOut-of-bounds read parsing FTP directory listings leaks memory from other transactions
