In Argo Workflows versions prior to 3.7.14 and 4.0.5 a high severity vulnerability CVE-2026-42296 was detected. This vulnerability, which is an incomplete fix for CVE-2026-31892, allows users with “create Workflow” permissions to bypass the template Referencing Strict mode. By exploiting this, attackers can gain host network access, switch service accounts, override pod security contexts, add tolerations to schedule on control-plane nodes, or enable service account token mounting. Environments relying solely on Argo’s Strict mode without additional Kubernetes-level controls (like PodSecurity admission) are fully exposed. To address this issue, users should upgrade Argo Workflows to versions 3.7.14 or 4.0.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-42296.
Read more Developer ToolsIn etcd versions prior to 3.4.44, 3.5.30, and 3.6.11 a medium severity vulnerability CVE-2026-44283 was detected. This vulnerability allows an authenticated user without sufficient read or lease-related permissions to access unauthorized data or attach leases. This occurs because read access via PrevKv or lease attachments in Put requests within transaction operations can bypass RBAC authorization checks. To address this issue, users should upgrade etcd to versions 3.4.44, 3.5.30, or 3.6.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44283.
Read more Developer ToolsIn authentik versions 2025.12.4 and prior, and 2026.2.0-rc1 through 2026.2.2 a high severity vulnerability CVE-2026-40165 was detected. This vulnerability allows an attacker to bypass authentication and gain unauthorized access to other user accounts. This occurs because an attacker can inject an XML comment into the SAML NameID value, causing authentik to truncate the identifier to the portion before the comment. The issue can be exploited if the attacker has an account on a SAML Source with XML Signing enabled and the ability to modify their NameID value. To address this issue, users should upgrade authentik to versions 2025.12.5 or 2026.2.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-40165.
Read more SecurityIn Discourse versions prior to 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1 a low severity vulnerability CVE-2026-34154 was detected. This vulnerability allows users to bypass subscription access controls and gain unauthorized access to subscription-gated groups without completing payment. This occurs due to a flaw in the discourse-subscriptions plugin. To address this issue, users should upgrade Discourse to versions 2026.1.4, 2026.3.1, 2026.4.1, or 2026.5.0-latest.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-34154.
Read more CommunicationIn Jenkins version 1.498 a medium severity vulnerability CVE-2017-1000362 was detected. This vulnerability allows attackers with local filesystem access to expose sensitive information because the re-key admin monitor created a world-readable backup directory containing all old secrets and their encryption key. These backups were not automatically removed. There’s no fix available for this issue at the moment. Additionally, administrators are advised to manually check and delete the $JENKINS_HOME/jenkins.security.RekeySecretAdminMonitor/backups directory if present. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-1000362.
Read more Developer ToolsIn Joomla! versions before 3.8.2 a high severity vulnerability CVE-2017-16634 was detected. This vulnerability allows third parties to bypass a user’s two-factor authentication (2FA) method, potentially leading to unauthorized account access. To address this issue, users should upgrade Joomla! to version 3.8.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-16634.
Read more CMSIn GitLab EE versions 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 a low severity vulnerability CVE-2026-7471 was detected. This vulnerability allows an authenticated user with control of a virtual registry upstream to make unauthorized requests to internal hosts, potentially leading to Server-Side Request Forgery (SSRF). This occurs due to improper validation of the upstream requests. To address this issue, users should upgrade GitLab EE to versions 18.9.7, 18.10.6, or 18.11.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-7471.
Read more Developer ToolsIn Harbor versions through 1.3.0-rc4 a medium severity vulnerability CVE-2017-17697 was detected. This vulnerability allows an attacker to conduct Server-Side Request Forgery (SSRF) attacks via the endpoint parameter to the /api/targets/ping endpoint. This occurs due to a flaw in the Ping() function in the ui/api/target.go file. To address this issue, users should upgrade Harbor to version 1.3.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-17697.
Read more Developer ToolsIn CKAN versions prior to 2.10.10 and 2.11.5 a critical severity vulnerability CVE-2026-42031 was detected. This vulnerability allows unauthenticated attackers to inject SQL in order to gain access to private resources and PostgreSQL system information due to a flaw in the datastore_search_sql function. To address this issue, users should upgrade CKAN to versions 2.10.10 or 2.11.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-42031.
Read more Data Analytics