AISLE CVE Discoveries
CVEs our AI-native engine discovered in the world's most audited code, responsibly disclosed to maintainers.
September 2026
53 CVEsLinux
1rpm
3flatpak-builder
1glibc
131- CVE-2026-194997.7
Buffer overflow in strfmon and strfmon_l right-justification padding
- CVE-2026-804895.9
EUC_JISX0213 decoding may hang on crafted input
- CVE-2026-771175.9
SHIFT_JISX0213 decoding may hang on crafted input
- CVE-2026-195425.6
Stack-based out-of-bounds write in tdelete during tree rebalancing
- CVE-2026-958183.6
AT_SECURE program buffer overflow via $ORIGIN processing
cockpit
171- CVE-2026-911497.5
Denial of service via unbounded connection thread spawning
- CVE-2026-912026.1
Arbitrary file ownership change via symlink following in privileged paste
- CVE-2026-912056.0
Local attacker can hijack file ownership via symlink race
- CVE-2026-912036.0
Arbitrary file ownership and permission modification via symlink race condition
- CVE-2026-911475.9
Dnial of service in `cockpit-ws` due to url-root handling without a trailing slash
- CVE-2026-927685.5
Sensitive data exposure via command-line arguments
- CVE-2026-927475.0
Sensitive data exposure of guest credentials via json argument in process list
- CVE-2026-927455.0
Information disclosure of rhsm offline token via process arguments
- CVE-2026-911423.6
Integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 builds
Broker-J
11curl
123libXi
15- CVE-2026-935437.4
Out-of-bounds read in libXi's XI2 class parser
- CVE-2026-942816.5
Out-of-bounds read in libXi's XListInputDevices() class parsing
- CVE-2026-935456.5
Out-of-bounds read in libXi's XListInputDevices()
- CVE-2026-935446.5
Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing
- CVE-2026-935426.5
Out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes()
- CVE-2026-935416.5
Out-of-bounds read in libXi's XQueryDeviceState()
undici
11environment-modules
1snipe-it
31phpMyFAQ
2device-mapper-multipath:
1sssd
5- CVE-2026-909955.5
Denial of service due to null pointer dereference in pam responder
- CVE-2026-904625.4
Fail-open in ldap ppolicy access check allows continued authorization
- CVE-2026-909964.0
Denial of service in nss responder via crafted zero-length requests
- CVE-2026-909944.0
Denial of service via malformed pam v1 requests
- CVE-2026-904634.0
OOB read in nss service request parsers
libstoragemgmt
1August 2026
71 CVEsFFmpeg
151- CVE-2026-751439.8
FFmpeg Heap Buffer Overflow via RIST Protocol Reader
- CVE-2026-751448.5
FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer
- CVE-2026-751428.5
FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c
- CVE-2026-751418.5
FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing
- CVE-2026-751468.1
FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c
- CVE-2026-751477.1
FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c
- CVE-2026-751455.8
FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer
FreeBSD
4rodauth
14- CVE-2026-824669.4
Rodauth before 2.46.0 Authentication Bypass via webauthn_login
- CVE-2026-824705.4
Rodauth before 2.47.0 TOTP Code Reuse via Drift Window
- CVE-2026-824695.4
Rodauth before 2.47.0 Authentication Bypass via jwt_refresh
- CVE-2026-824684.9
Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type
- CVE-2026-824674.9
Rodauth before 2.47.0 Open Redirect via Return-to Path
phpMyFAQ
2Roundcube
11pac4j
23- CVE-2026-824638.6
pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check
- CVE-2026-824618.6
pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token
- CVE-2026-824656.9
pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequest
- CVE-2026-824626.9
pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution
- CVE-2026-824646.1
pac4j-core before 6.5.6 Open Redirect via Backslash Logout
Wireshark
4101- CVE-2026-768868.1
Heap-based Buffer Overflow in Wireshark
- CVE-2026-769287.5
NULL Pointer Dereference in Wireshark
- CVE-2026-768807.5
Out-of-bounds Write in Wireshark
- CVE-2026-768797.5
Stack-based Buffer Overflow in Wireshark
- CVE-2026-196966.6
Out-of-bounds write in BLF file parsing
- CVE-2026-769245.5
Out-of-bounds Read in Wireshark
- CVE-2026-769235.5
Out-of-bounds Read in Wireshark
- CVE-2026-769225.5
NULL Pointer Dereference in Wireshark
- CVE-2026-769215.5
Use After Free in Wireshark
- CVE-2026-769195.3
Use of Uninitialized Variable in Wireshark
- CVE-2026-769294.7
Out-of-bounds Read in Wireshark
- CVE-2026-769274.7
NULL Pointer Dereference in Wireshark
- CVE-2026-769204.7
Out-of-bounds Write in Wireshark
- CVE-2026-768814.7
NULL Pointer Dereference in Wireshark
- CVE-2026-769263.1
Reachable Assertion in Wireshark
freeipa
22- CVE-2026-731987.5
Unauthenticated DoS in via unbounded request body read
- CVE-2026-731977.5
Unauthenticated DoS in `/ipa/migration/migration.py` via unbounded request body read
- CVE-2026-731996.5
Null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value
- CVE-2026-731964.3
Authenticated DoS in `otptoken-add` via unbounded otp key decoding/re-encoding
Iperf3
11libkcapi
12RabbitMQ
122- CVE-2026-674197.1
Consecutive topic wildcards cause combinatorial routing work
- CVE-2026-674165.3
Descriptor prefix collision in the AMQP 1.0 parser lets stored messages crash consumers
- CVE-2026-674214.5
Stored HTML Injection in RabbitMQ Management OAuth Error Handling
- CVE-2026-674202.3
OAuth credential refresh retains revoked runtime tags
- CVE-2026-674182.3
Inapplicable PUBLISH property disconnects matching subscribers
sblim-sfcb
2open-iscsi
3stunnel
2sblim-cmpi-base
1OpenSSH
21- CVE-2026-556555.0
Local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions
- CVE-2026-556534.3
Double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service
- CVE-2026-556543.7
Heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination
July 2026
43 CVEscurl
33- CVE-2026-105369.8
Use-after-free in HTTP/2 stream-dependency handling after curl_easy_reset()
- CVE-2026-89259.8
Double free of the GSASL context during SASL authentication cleanup
- CVE-2026-89269.1
Password for another .netrc user sent when the URL specifies only a username
- CVE-2026-89327.5
Connection reuse ignores changed client certificate and private key TLS options
- CVE-2026-95477.4
Known-host key type mismatch silently accepted via the CURLOPT_SSH_KEYFUNCTION callback
- CVE-2026-90807.3
Use-after-free when curl_easy_pause() is called from the socket callback
Ninja Forms
221- CVE-2026-650499.3
Site-scoped capability check in nf_delete_all_data enables network-wide data deletion
- CVE-2026-650489.3
Unauthenticated stored XSS via crafted Repeatable Fieldset submission indexes
- CVE-2026-650528.7
Payment total tampering via fail-open get_calc_value() in ListSelect and ListRadio fields
- CVE-2026-650507.1
Missing authorization in the submissions-table block exposes form submissions to visitors
- CVE-2026-650516.9
Validation bypass via client-controlled field metadata in the AJAX submission handler
FFmpeg
6- CVE-2026-648358.8
Out-of-bounds read and write in the ADX audio decoder via a mid-stream channel layout change
- CVE-2026-648328.8
Double free in the NVDEC hardware decoder when no decoder surfaces remain
- CVE-2026-648318.8
Stack buffer overflow in the Vulkan HEVC decoder via oversized vps_num_hrd_parameters
- CVE-2026-648308.8
Heap buffer overflow in the VobSub subtitle demuxer via excessive distinct stream IDs
- CVE-2026-648348.7
Infinite loop in rtp_asf_fix_header() via an undersized ASF chunksize
- CVE-2026-648337.1
Out-of-bounds read in the S/PDIF muxer via an oversized DTS core_size value
Foreman
13- CVE-2026-51368.8
Privilege escalation to administrator via unvalidated usergroup role assignments
- CVE-2026-51426.5
Cross-tenant private SSH key disclosure via taxonomy scoping bypass
- CVE-2026-51356.5
Authorization bypass lets host editors retarget lookup value overrides to other hosts
- CVE-2026-51384.3
Cross-tenant infrastructure metadata disclosure via unvalidated IDs in taxonomy_scope
libssh
111- CVE-2026-598518.8
Missing Kerberos principal check in the gssapi-keyex path allows login as arbitrary users
- CVE-2026-598485.3
Unbounded memory growth in SFTP clients from responses with unknown request IDs
- CVE-2026-598493.1
Infinite loop in automatic certificate authentication leading to denial of service
cJSON
21- CVE-2026-672158.7
Stack exhaustion via uncontrolled recursion when applying crafted JSON Patch documents
- CVE-2026-672168.2
Exponential runtime in cJSON_Compare() on deeply nested JSON, leading to denial of service
- CVE-2026-672176.9
Non-atomic JSON Patch application destroys target document members on failed operations
Gitea
1yggdrasil-worker-package-manager
1gnome-remote-desktop
1libsolv
1rpcbind
2saleor/saleor
1ansible-collection-redhat-leapp
2June 2026
20 CVEsApache HTTP Server
11MariaDB
11Pacemaker
1openemr
1ImageMagick
2OpenSSL
11phpBB
1alsa-lib
1Capstone
2n8n
1May 2026
29 CVEsGnuTLS
14- CVE-2026-420109.8
Authentication bypass via NUL character in RSA-PSK usernames
- CVE-2026-420138.2
Certificate validation falls back to Common Name checks on an oversized SAN
- CVE-2026-52608.2
Heap overread in RSA key exchange with a PKCS#11-backed key via a short premaster secret
- CVE-2026-420097.5
Denial of service via duplicate sequence numbers in DTLS packet reordering
- CVE-2026-291697.5
NULL pointer dereference in mod_dav_lock via a malicious request
FreeBSD
12- CVE-2026-394618.8
Stack buffer overflow in libcasper via file descriptors exceeding FD_SETSIZE in select()
- CVE-2026-452546.5
Privilege widening in cap_net when keys omitted from a new limit default to allow-any
- CVE-2026-452525.5
Heap overflow in FUSE_LISTXATTR handling via a non-NUL-terminated attribute list
PostgreSQL
2FOG
31- CVE-2026-476888.2
Unauthenticated deletion of host AES keys and power schedules via clearAES and clearPMTasks
- CVE-2026-476877.3
Stored XSS in the Inventory Report via unescaped option labels in selectForm()
- CVE-2026-476857.3
Stored XSS in the Host Management page via the unauthenticated inventory endpoint
- CVE-2026-476894.6
Stored XSS via unescaped inventory data in buildRow() on the Group Inventory tab
libsolv
12Apache HTTP Server
11mautic/core
11Drupal core
1Joomla! CMS
1glib-networking
1Safari
1April 2026
22 CVEshackage-server
2OTP
111GnuTLS
111OpenSSL
5- CVE-2026-283878.1
Use-after-free in client-side DANE TLSA certificate checking
- CVE-2026-283907.5
NULL pointer dereference when processing CMS KeyTransportRecipientInfo
- CVE-2026-283897.5
NULL pointer dereference when processing CMS KeyAgreeRecipientInfo
- CVE-2026-283887.5
NULL pointer dereference when processing a delta CRL missing the CRL Number extension
- CVE-2026-283867.5
Out-of-bounds read when processing partial AES-CFB128 blocks on AVX-512 systems
FreeBSD
3- CVE-2026-425128.1
Heap buffer overflow in dhclient's environment array resizing via a crafted packet
- CVE-2026-425118.1
dhclient.conf directive injection via the BOOTP file field, leading to root code execution
- CVE-2026-394577.8
Stack buffer overflow in libnv via file descriptors exceeding FD_SETSIZE in select()
MySQL Server
3MariaDB
1See our CNA Disclosure Policy

