Skip to content
Threat Feed

Tag

Application-Security

12 briefs RSS
high advisory

Denial of Service Vulnerability in Quarkus WebSockets Next

A vulnerability in quarkus-websockets-next allows a remote attacker to cause a Denial of Service via heap exhaustion by streaming WebSocket messages faster than the application can process them.

Quarkus +1 denial-of-service java application-security web-application security-flaw authorization-bypass
1t 1c updated
high advisory

Multiple Vulnerabilities in ImageMagick

ImageMagick contains multiple vulnerabilities that could allow an attacker to trigger information disclosure, denial-of-service, or remote code execution by processing specially crafted image files.

ImageMagick vulnerability application-security
1t
high advisory

Arbitrary File Upload Vulnerability in Gravity Forms

An arbitrary file upload vulnerability in the Gravity Forms WordPress plugin (<= 3.0.2) allows unauthenticated attackers to write arbitrary files to the temporary upload directory, potentially leading to remote code execution or stored XSS.

Gravity Forms +1 wordpress vulnerability rce xss application-security
1r 3t 1c updated
high advisory

Multiple Vulnerabilities in GitLab

GitLab is affected by multiple vulnerabilities that allow remote code execution, denial of service, data manipulation, and security control bypass.

GitLab vulnerability application-security
2t
critical advisory

Unauthenticated SQL Injection in GeoTools PostGIS DataStore

A critical unauthenticated SQL injection vulnerability (CVE-2026-76904) in the GeoTools library allows remote attackers to execute arbitrary SQL via the jsonArrayContains filter function.

PoC GeoTools sql-injection vulnerability application-security
1t 1c updated
critical advisory

Authentication Bypass in SiYuan Publish API

SiYuan versions prior to 3.7.4 contain an authentication bypass vulnerability allowing unauthenticated remote attackers to retrieve decrypted content from encrypted notebooks.

SiYuan +3 access-control web-vulnerability authentication-bypass information-disclosure api-security remote-code-execution vulnerability pdf-processing +9
7r 19t 5c updated
high advisory

Vantage6 Algorithm Developer Can Edit Other Developers' Pending Algorithms

An algorithm developer in the vantage6 system can modify another developer's algorithm metadata or Docker image tag, even when that algorithm is pending review, allowing an attacker with low privileges to replace an approved algorithm with an unapproved or malicious image.

vantage6 vulnerability supply-chain authorization application-security
1t
high advisory

n8n Shared Credential Leakage via HTTP Request Pagination Vulnerability

An authenticated n8n user with 'use-only editor access' can exploit CVE-2026-59209 in shared workflows when `N8N_EXPRESSION_ENGINE=vm` is enabled, allowing them to read sensitive HTTP Header Auth credentials from the `$request.headers` object within a paginated HTTP Request node's expression and exfiltrate them, bypassing credential domain restrictions.

n8n +2 vulnerability credential-access data-exfiltration application-security prototype-pollution authentication-bypass data-enumeration
5t 1c
high advisory

Race Condition in n8n Git Clone Node Leads to Remote Code Execution

A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the Git node's clone operation in n8n versions prior to 1.123.64, 2.29.8, and 2.30.1. This vulnerability allows authenticated users to bypass path restrictions by swapping a validated directory for a symlink, enabling them to plant a crafted repository in the community node directory. Upon the next restart, n8n loads this as a custom node, leading to arbitrary JavaScript execution on the server, affecting both self-hosted and cloud instances.

n8n < 1.123.64 +2 race-condition rce n8n application-security cloud-security
3t
high advisory

Cherry Studio Remote Code Execution Vulnerability (CVE-2026-40501)

A remote code execution vulnerability, CVE-2026-40501, exists in Cherry Studio versions 1.2.2 through 1.9.12 due to improper Electron BrowserWindow configuration, allowing remote attackers to execute arbitrary code by injecting malicious JavaScript through controlled search provider content, thereby gaining full Node.js privileges and accessing system resources.

Cherry Studio 1.2.2 +1 remote-code-execution electron-vulnerability application-security
1r 1t 1c
high advisory

OpenClaw Scoped Chat Route Inheritance Could Bypass Admin Command Scope Gates

A vulnerability in OpenClaw allows an attacker with `operator.write` privileges to bypass intended administrative command scope gates by delivering a scoped Gateway `chat.send` request through an inherited external route, leading to unauthorized execution of critical administrative commands.

openclaw vulnerability privilege-escalation application-security
1t
medium advisory

Okta Application Modified or Deleted

Detects when an Okta application is modified or deleted, potentially indicating unauthorized changes or removal of critical applications.

Okta application-security identity-management
2r 1t