Skip to content

Commit 80ab0af

Browse files

File tree

Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2xgv-7q8p-67gc",
4+
"modified": "2026-09-06T18:34:39Z",
5+
"published": "2026-09-06T18:34:39Z",
6+
"aliases": [
7+
"CVE-2026-80230"
8+
],
9+
"details": "When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80230"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://hackerone.com/reports/3969300"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://curl.se/docs/CVE-2026-80230.html"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://curl.se/docs/CVE-2026-80230.json"
28+
}
29+
],
30+
"database_specific": {
31+
"cwe_ids": [],
32+
"severity": null,
33+
"github_reviewed": false,
34+
"github_reviewed_at": null,
35+
"nvd_published_at": "2026-09-06T18:17:22Z"
36+
}
37+
}
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-3968-82gf-vhpr",
4+
"modified": "2026-09-06T18:34:38Z",
5+
"published": "2026-09-06T18:34:38Z",
6+
"aliases": [
7+
"CVE-2026-13608"
8+
],
9+
"details": "A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13608"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://hackerone.com/reports/3822248"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://curl.se/docs/CVE-2026-13608.html"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://curl.se/docs/CVE-2026-13608.json"
28+
}
29+
],
30+
"database_specific": {
31+
"cwe_ids": [],
32+
"severity": null,
33+
"github_reviewed": false,
34+
"github_reviewed_at": null,
35+
"nvd_published_at": "2026-09-06T18:17:19Z"
36+
}
37+
}
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-3hpw-4mfr-9f85",
4+
"modified": "2026-09-06T18:34:39Z",
5+
"published": "2026-09-06T18:34:39Z",
6+
"aliases": [
7+
"CVE-2026-82209"
8+
],
9+
"details": "When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`).",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82209"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://hackerone.com/reports/3972385"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://curl.se/docs/CVE-2026-82209.html"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://curl.se/docs/CVE-2026-82209.json"
28+
}
29+
],
30+
"database_specific": {
31+
"cwe_ids": [],
32+
"severity": null,
33+
"github_reviewed": false,
34+
"github_reviewed_at": null,
35+
"nvd_published_at": "2026-09-06T18:17:22Z"
36+
}
37+
}
Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-6fjm-7mv9-c325",
4+
"modified": "2026-09-06T18:34:38Z",
5+
"published": "2026-09-06T18:34:38Z",
6+
"aliases": [
7+
"CVE-2026-82751"
8+
],
9+
"details": "Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account.\n\nWhen the server sponsors Tempo payments, MPP.Methods.Tempo.FeePayerPolicy.measure/3 in lib/mpp/methods/tempo/fee_payer_policy.ex bounds the gas fields, the fee budget, the validity window and the access list of the client-signed 0x76 envelope, but does not check whether the envelope carries the optional key_authorization field. A client can attach a fully signed key authorization, provisioning a new access key with token spending limits on its own account, alongside the normal payment call. The key and each limit entry are persistent storage writes billed as intrinsic gas to the sponsor, bounded only by the gas_limit ceiling. At the reporter's default of one key with three token limits the sponsored cost rises from about 46,587 gas to about 1,808,700 gas, and the client keeps a valid access key it paid nothing for.\n\nThis issue affects mpp: from 0.2.0 before 0.16.1.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V4",
13+
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "WEB",
20+
"url": "https://github.com/ZenHive/mpp/security/advisories/GHSA-rpwj-vrf7-4x36"
21+
},
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82751"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/ZenHive/mpp/commit/0482572b47e1ffe1537ab80ab613d47b92833c2d"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://cna.erlef.org/cves/CVE-2026-82751.html"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-82751"
37+
}
38+
],
39+
"database_specific": {
40+
"cwe_ids": [
41+
"CWE-1284"
42+
],
43+
"severity": "HIGH",
44+
"github_reviewed": false,
45+
"github_reviewed_at": null,
46+
"nvd_published_at": "2026-09-06T17:17:56Z"
47+
}
48+
}
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-8rq8-f59m-9cjg",
4+
"modified": "2026-09-06T18:34:39Z",
5+
"published": "2026-09-06T18:34:39Z",
6+
"aliases": [
7+
"CVE-2026-82208"
8+
],
9+
"details": "With the wolfSSL backend, when CA caching is enabled and an\n`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can\nsilently reinstall the cached store after the callback returns. A certificate\ntrusted by the cached store but rejected by the callback-selected store is\nthen incorrectly accepted.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82208"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://hackerone.com/reports/3973090"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://curl.se/docs/CVE-2026-82208.html"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://curl.se/docs/CVE-2026-82208.json"
28+
}
29+
],
30+
"database_specific": {
31+
"cwe_ids": [],
32+
"severity": null,
33+
"github_reviewed": false,
34+
"github_reviewed_at": null,
35+
"nvd_published_at": "2026-09-06T18:17:22Z"
36+
}
37+
}
Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-j8qw-c658-vr9r",
4+
"modified": "2026-09-06T18:34:38Z",
5+
"published": "2026-09-06T18:34:38Z",
6+
"aliases": [
7+
"CVE-2026-83534"
8+
],
9+
"details": "PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83534"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/666"
25+
}
26+
],
27+
"database_specific": {
28+
"cwe_ids": [
29+
"CWE-250"
30+
],
31+
"severity": "MODERATE",
32+
"github_reviewed": false,
33+
"github_reviewed_at": null,
34+
"nvd_published_at": "2026-09-06T16:16:50Z"
35+
}
36+
}
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-jrp3-jq4v-w9gc",
4+
"modified": "2026-09-06T18:34:39Z",
5+
"published": "2026-09-06T18:34:39Z",
6+
"aliases": [
7+
"CVE-2026-80229"
8+
],
9+
"details": "When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80229"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://hackerone.com/reports/3969255"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://curl.se/docs/CVE-2026-80229.html"
24+
},
25+
{
26+
"type": "WEB",
27+
"url": "https://curl.se/docs/CVE-2026-80229.json"
28+
}
29+
],
30+
"database_specific": {
31+
"cwe_ids": [],
32+
"severity": null,
33+
"github_reviewed": false,
34+
"github_reviewed_at": null,
35+
"nvd_published_at": "2026-09-06T18:17:22Z"
36+
}
37+
}
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-pvcx-w2qj-fpm3",
4+
"modified": "2026-09-06T18:34:39Z",
5+
"published": "2026-09-06T18:34:39Z",
6+
"aliases": [
7+
"CVE-2026-86220"
8+
],
9+
"details": "A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86220"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/justconter/_CVE/issues/1"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://vuldb.com/cve/CVE-2026-86220"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://vuldb.com/submit/897734"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://vuldb.com/vuln/399373"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://vuldb.com/vuln/399373/cti"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://www.sourcecodester.com"
49+
}
50+
],
51+
"database_specific": {
52+
"cwe_ids": [
53+
"CWE-74"
54+
],
55+
"severity": "MODERATE",
56+
"github_reviewed": false,
57+
"github_reviewed_at": null,
58+
"nvd_published_at": "2026-09-06T18:17:23Z"
59+
}
60+
}
Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-q4f3-jf9f-788f",
4+
"modified": "2026-09-06T18:34:38Z",
5+
"published": "2026-09-06T18:34:38Z",
6+
"aliases": [
7+
"CVE-2026-82750"
8+
],
9+
"details": "Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing.\n\nWhen the server sponsors Tempo payments, MPP.Methods.Tempo.FeePayerPolicy.measure/3 in lib/mpp/methods/tempo/fee_payer_policy.ex bounds the gas fields, the fee budget, the validity window and the access list of the client-signed 0x76 envelope, but never reads its aa_authorization_list field. Every signed delegation in that list is charged as intrinsic gas before the payment call runs, so a client attaching delegations from throwaway authority keys makes the sponsor pay for them within the default gas_limit ceiling. At the reporter's default of seven entries the sponsored cost rises from about 46,575 gas to about 1,884,087 gas. Because each entry is applied as a persistent set-code delegation, a client can also upgrade its own accounts to delegated code at the sponsor's expense.\n\nThis issue affects mpp: from 0.2.0 before 0.16.1.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V4",
13+
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "WEB",
20+
"url": "https://github.com/ZenHive/mpp/security/advisories/GHSA-5qrp-r24c-w6jr"
21+
},
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82750"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/ZenHive/mpp/commit/0482572b47e1ffe1537ab80ab613d47b92833c2d"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://cna.erlef.org/cves/CVE-2026-82750.html"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-82750"
37+
}
38+
],
39+
"database_specific": {
40+
"cwe_ids": [
41+
"CWE-1284"
42+
],
43+
"severity": "HIGH",
44+
"github_reviewed": false,
45+
"github_reviewed_at": null,
46+
"nvd_published_at": "2026-09-06T17:17:55Z"
47+
}
48+
}

0 commit comments

Comments
 (0)