Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Book a demo
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash

Our news and updates

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Choose category
    • Communication
      • Communication
    • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Customer Service
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • CMS
      • Networking
      • Storage
      • Security
    • DevOps
      • Virtualization
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    2 Jul 2026 Data Management and Analytics
    Elasticsearch: Denial of Service via Unrestricted Resource Allocation in Machine Learning

    In Elasticsearch versions up to 8.19.16/9.3.5/9.4.2 a medium severity vulnerability CVE-2026-56149 was detected. This vulnerability allows an authenticated user with elevated privileges to cause a Denial of Service (DoS) by rendering the affected node unavailable. This occurs due to an Allocation of Resources Without Limits or Throttling (CWE-770) flaw in the processing of machine learning requests. By submitting a specially crafted machine learning request, an attacker can trigger excessive memory allocation (CAPEC-130), leading to resource exhaustion and the subsequent unavailability of the Elasticsearch node. There’s no fix available for this issue at the moment. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-56149.

    Read more
    Data Analytics
    2 Jul 2026 Data Management and Analytics
    Docling: Information Disclosure and DoS via Unsafe XML Parsing in METS-GBS Backend

    In Docling versions 2.45.0 to before 2.91.0 a medium severity vulnerability CVE-2026-44018 was detected. This vulnerability allows an attacker to read sensitive files, exhaust system resources, or cause application crashes, leading to unauthorized information disclosure and Denial of Service (DoS). This occurs due to unsafe archive extraction and a lack of security controls during XML parsing in the METS-GBS backend. By crafting a malicious METS-GBS archive and exploiting the input document format detection mechanisms (such as via XML External Entity (XXE) injection or archive bombs), an attacker can compromise the parsing process. To address this issue, users should upgrade Docling to version 2.91.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44018.

    Read more
    Data Analytics
    2 Jul 2026 Data Management and Analytics
    ChromaDB: Remote Code Execution via Malicious Model Repository

    In ChromaDB versions 0.4.17 and later a high severity vulnerability CVE-2026-45833 was detected. This vulnerability allows an authenticated attacker with UPDATE_COLLECTION permissions to execute arbitrary code on the server, leading to Remote Code Execution (RCE). This occurs due to a code injection flaw when the application handles model repositories. By sending a malicious model repository to the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} endpoint and setting the trust_remote_code parameter to true, an attacker can trick the system into executing their malicious payload.There’s no fix available for this issue at the moment. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-45833.

    Read more
    Database
    2 Jul 2026 DevOps
    Appsmith: Remote Code Execution via Exposed Supervisord XML-RPC Interface

    In Appsmith versions prior to 2.1 a high severity vulnerability CVE-2026-50189 was detected. This vulnerability allows an authenticated administrator to execute arbitrary OS commands inside the Docker container, leading to Remote Code Execution (RCE). This occurs because the bundled supervisord exposes an XML-RPC interface that is reachable from outside the container via a Caddy reverse-proxy route at /supervisor/*. Additionally, the required authentication password (APPSMITH_SUPERVISOR_PASSWORD) is inadvertently exposed via the GET /api/v1/admin/env endpoint. By combining these issues, an attacker can retrieve the password, authenticate, and send maliciously crafted XML-RPC calls (such as twiddler.addProgramToGroup) to execute commands on the underlying system. To address this issue, users should upgrade Appsmith to version 2.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-50189.

    Read more
    Application Development
    1 Jul 2026 DevOps
    Budibase: Unauthenticated NoSQL Injection via Published App Query Templates

    In Budibase versions prior to 3.39.12 a critical severity vulnerability CVE-2026-54350 was detected. This vulnerability allows an unauthenticated attacker to read or modify all documents within the backing databases (such as MongoDB, CouchDB, Elasticsearch, or DynamoDB). This occurs due to a NoSQL operator injection flaw when processing published-app query templates. The application fails to properly escape JSON metacharacters (such as quotes and braces) when substituting user-controlled parameters into the raw JSON query body. By injecting these characters, an attacker can manipulate the parsed JSON object to include NoSQL operators (e.g., $exists: true), overriding the intended filters and expanding the query scope to the entire collection. Furthermore, endpoints associated with PUBLIC queries do not enforce CSRF protection or require an active session. To address this issue, users should upgrade Budibase to version 3.39.12 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-54350.

    Read more
    Application Development
    1 Jul 2026 DevOps
    Helm: Arbitrary File Write via Path Traversal in Plugin Metadata

    In Helm versions 4.0.0 to before 4.1.4 a high severity vulnerability CVE-2026-35204 was detected. This vulnerability allows an attacker to write the contents of a plugin to arbitrary filesystem locations outside the designated Helm plugin directory. This occurs due to a path traversal flaw when installing or updating a specially crafted Helm plugin. If the version field within the plugin’s plugin.yaml file contains POSIX dot-dot path separators (e.g., /../), Helm fails to properly sanitize the path before writing files. To address this issue, users should upgrade Helm to version 4.1.4 or later. As a temporary workaround, users can manually validate that the plugin.yaml of any Helm plugin does not include path separators in the version field before installation. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-35204.

    Read more
    Developer Tools
    1 Jul 2026 Data Management and Analytics
    Docling: Arbitrary File Write via Zip Slip in EasyOCR Model Download

    In Docling versions prior to 2.91.0 a high severity vulnerability CVE-2026-44017 was detected. This vulnerability allows an attacker to write arbitrary files to any location writable by the process, potentially leading to Remote Code Execution (RCE) or persistent backdoors. This occurs due to a Zip Slip flaw in the EasyOCR model download functionality, where ZIP archives are extracted without properly validating member paths. If an attacker successfully compromises the model download source—such as through a supply chain attack, DNS spoofing, or a Man-in-the-Middle (MITM) attack—they can deliver a maliciously crafted ZIP file containing directory traversal sequences. To address this issue, users should upgrade Docling to version 2.91.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44017.

    Read more
    Data Analytics
    1 Jul 2026 DevOps
    Gogs: Arbitrary File Write via Symlink Traversal in UploadRepoFiles

    In Gogs versions prior to 0.14.3 a critical severity vulnerability CVE-2026-52811 was detected. This vulnerability allows an authenticated attacker with repository write access to write files outside the repository working tree, potentially leading to Remote Code Execution (RCE) or unauthorized SSH access. This occurs due to improper symlink validation in the UploadRepoFiles function, which only checks for symlinks at the leaf of the upload target rather than evaluating the entire path. By committing a parent directory symlink and then crafting a multipart upload with a filename containing a literal backslash (which gets converted to a directory separator), an attacker can redirect the file write through the symlink. Because the system opens the destination without preventing symlink following (missing O_NOFOLLOW), the attacker can overwrite sensitive files anywhere the gogs user has write permissions, such as ~git/.ssh/authorized_keys for SSH access or <repo>.git/hooks/post-receive for RCE on the next push. To address this issue, users should upgrade Gogs to version 0.14.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-52811.

    Read more
    Developer Tools
    1 Jul 2026 DevOps
    Gitea: Cross-Repository IDOR in Git LFS Lock Deletion

    In Gitea versions before 1.25.4 a critical severity vulnerability CVE-2026-20897 was detected. This vulnerability allows an authenticated user with write access to one repository to delete Git LFS locks belonging to other repositories, leading to unauthorized data modification and broken access control. This occurs due to an Insecure Direct Object Reference (IDOR) flaw, where the application does not properly validate repository ownership during the Git LFS lock deletion process. To address this issue, users should upgrade Gitea to a patched version 1.25.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-20897.

    Read more
    Developer Tools
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base

    © HOSSTED 2026 All rights reserved

    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    Cookie Settings

    We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}