Overview
Description
Statistics
- 1 Post
Fediverse
runc, the low-level OCI runtime under Docker and Kubernetes, shipped 1.4.3 and 1.3.6 plus the 1.5.0-rc.3 candidate on June 13. All carry a low-severity fix for CVE-2026-41579, where a container image with a /dev symlink could get limited write access to the host filesystem. The releases also reuse a single tmpfs instance when masking directories, cutting superblock overhead for Kubernetes nodes. How do you prioritize a low-severity flaw in something this foundational?
#containers #Kubernetes
Overview
- ThemeGrill
- Masteriyo - LMS
- learning-management-system
Description
Statistics
- 1 Post
Fediverse
CVE-2026-49111 - Privilege Escalation in Themegrill Masteriyo LMS. CVSS 8.8. Unpatched in versions through 2.2.0. Update immediately. #CVE #WordPress #infosec
Overview
Description
Statistics
- 1 Post
Overview
- Tecrail
- Responsive FileManager
Description
Statistics
- 1 Post
Fediverse
🚨 CVE-2026-5482 (CRITICAL): Tecrail Responsive FileManager ≤9.14.0 lets unauth'd attackers upload dangerous files via dialog.php, leading to RCE. Project is unmaintained — no patch. Restrict access & monitor now. https://radar.offseq.com/threat/cve-2026-5482-cwe-434-unrestricted-upload-of-file--d1d3c74e #OffSeq #RCE #Vulnerability
Overview
- webpack-dev-server
- webpack-dev-server
Description
Statistics
- 2 Posts
Fediverse
🚨 Medium-severity security fix in webpack-dev-server@5.2.5 just released!
Patches CVE-2026-9595. webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies.
https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79
Overview
Description
Statistics
- 1 Post
Bluesky
Overview
Description
Statistics
- 1 Post
Overview
- Apache Software Foundation
- Apache CXF
- org.apache.cxf:cxf-rt-rs-security-oauth2
Description
Statistics
- 1 Post
Fediverse
Apache CXF, the widely used Java services framework, has a batch of 2026 security advisories on its project page, with more than a dozen CVEs concentrated in OAuth2 and JAX-WS handling. The headline is CVE-2026-50623, an authentication bypass in the OAuth2 TokenIntrospectionService, alongside JNDI injection, XXE, and response-splitting fixes. Anyone exposing CXF endpoints should review the list and upgrade. How do you track CVEs in dependencies you did not pick directly?
#security #Java
Overview
Description
Statistics
- 2 Posts
Fediverse
🚨 High-severity security fix in multer@2.2.0 and multer@3.0.0-alpha.2 just released!
Patches CVE-2026-5079. multer vulnerable to Denial of Service via deeply nested field names.
https://github.com/expressjs/multer/security/advisories/GHSA-72gw-mp4g-v24j
Overview
- Edgar Rojas
- WooCommerce PDF Invoice Builder
- woo-pdf-invoice-builder
Description
Statistics
- 1 Post
Fediverse
🚨 CRITICAL: CVE-2026-52704 in WooCommerce PDF Invoice Builder ≤2.0.8 enables remote code execution via code injection (CWE-94). No patch yet — disable/remove plugin to prevent full system compromise. More info: https://radar.offseq.com/threat/cve-2026-52704-cwe-94-improper-control-of-generati-76aad4c5 #OffSeq #WordPress #Vuln