In Jenkins GitHub Branch Source Plugin version 1967.vdea_d580c1a_b_a_ and earlier a medium severity vulnerability CVE-2026-42522 was detected. This vulnerability allows attackers with Overall/Read permission to initiate connections to attacker-specified URLs using attacker-controlled GitHub App credentials due to a missing permission check. To address this issue, users should upgrade Jenkins GitHub Branch Source plugin to version 1967.1969.v205fd594c821. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-42522.
Read more Developer ToolsIn Jenkins GitHub Plugin version 1.46.0 and earlier a high severity vulnerability CVE-2026-42523 was detected. This vulnerability allows non-anonymous attackers with Overall/Read permission to execute stored cross-site scripting (XSS) due to improper handling of the current job URL in JavaScript used by the “GitHub hook trigger for GITScm polling” feature. To address this issue, users should upgrade Jenkins GitHub plugin to version 1.46.0.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-42523.
Read more Developer ToolsIn Mastodon versions prior to 4.5.9, 4.4.16, and 4.3.22 a high severity vulnerability CVE-2026-41259 was detected. This vulnerability allows attackers to bypass email domain restrictions by using specially crafted email addresses with characters interpreted differently by mail servers due to insufficient validation. To address this issue, users should upgrade Mastodon to versions 4.5.9, 4.4.16 or 4.3.22. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-41259.
Read more CommunicationIn Wazuh versions 4.8.0 up to before 4.14.4 a medium severity vulnerability CVE-2026-28221 was detected. This vulnerability allows attackers to trigger a stack-based buffer overflow in the print_hex_string() function via specially crafted input sent over the network prior to authentication, potentially leading to memory corruption, denial of service, or further exploitation. To address this issue, users should upgrade Wazuh to version 4.14.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-28221.
Read more SecurityIn Wazuh versions 4.4.0 up to before 4.14.4 a critical severity vulnerability CVE-2026-30893 was detected. This vulnerability allows authenticated cluster peers to perform path traversal attacks in the decompress_files() routine, enabling arbitrary file write outside the intended directory and potential remote code execution by overwriting loaded modules. To address this issue, users should upgrade Wazuh to version 4.14.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-30893.
Read more SecurityIn Wazuh versions 4.0.0 up to before 4.14.4 a medium severity vulnerability CVE-2026-41499 was detected. This vulnerability allows attackers to trigger heap-based out-of-bounds writes in the parse_uname_string() function due to unsafe handling of empty strings, resulting in unsigned integer underflow and writes before allocated buffers that can corrupt heap metadata and lead to denial of service or potential code execution. To address this issue, users should upgrade Wazuh to version 4.14.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-41499.
Read more SecurityIn Rocket.Chat versions prior to 8.4.0, prior to 8.3.2, prior to 8.2.2, prior to 8.1.3, prior to 8.0.4, prior to 7.13.6, prior to 7.12.7, prior to 7.11.7, and prior to 7.10.10 a medium severity vulnerability CVE-2026-29197 was detected. This vulnerability allows authenticated users without the proper permissions to read Apps-Engine logs due to a typo in the permission checks for the /api/apps/logs and /api/apps/:id/logs endpoints. To address this issue, users should upgrade Rocket.Chat to versions 8.4.0, 8.3.2, 8.2.2, 8.1.3, 8.0.4, 7.13.6, 7.12.7, 7.11.7, 7.10.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-29197.
Read more CommunicationIn Rocket.Chat versions prior to 8.3.0, prior to 8.2.1, prior to 8.1.2, prior to 8.0.3, prior to 7.13.5, prior to 7.12.6, prior to 7.11.6, and prior to 7.10.9 a critical severity vulnerability CVE-2026-29198 was detected. This vulnerability allows attackers to perform NoSQL injection in the OAuth flow, potentially leading to account takeover of the first user with a generated token when an OAuth application is configured. To address this issue, users should upgrade Rocket.Chat to versions 8.3.0, 8.2.1, 8.1.2, 8.0.3, 7.13.5, 7.12.6, 7.11.6 or 7.10.9. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-29198.
Read more CommunicationIn MinIO versions RELEASE.2023-05-18T00-05-36Z to versions prior to RELEASE.2026-04-11T03-20-12Z a high severity vulnerability CVE-2026-41145 was detected. This vulnerability allows attackers with a valid access key to bypass authentication and write arbitrary objects to any bucket without a secret key or valid cryptographic signature by exploiting the STREAMING-UNSIGNED-PAYLOAD-TRAILER code path. To address this issue, users should upgrade MinIO to versions RELEASE.2026-04-11T03-20-12Z or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-41145.
Read more Storage