In Apache Airflow versions prior to 3.2.0 medium severity vulnerability CVE-2025-66236 was detected. This vulnerability allows attackers to view secrets from the Airflow configuration file which were logged in plain text within the DAG run logs UI due to insufficient security model clarity and workload isolation. To address this issue users must upgrade to 3.2.0 version and follow the updated security model guidelines. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-66236.
Read more Data AnalyticsIn Zulip versions 1.4.0 to before 11.6 high severity vulnerability CVE-2026-25742 was detected. This vulnerability allows attackers to retrieve attachments originating from web-public streams and access topic history via the /users/me/<stream_id>/topics endpoint anonymously, even after spectator access has been disabled. To address this issue users must upgrade to 11.6 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25742.
Read more CommunicationIn Apache Airflow versions 3.0.0 through 3.1.8 high severity vulnerability CVE-2026-34538 was detected. This vulnerability allows attackers with low-privilege access (such as the Viewer role) to bypass authorization and retrieve sensitive XCom result values via the DagRun wait endpoint, which should be restricted under the FAB RBAC model. To address this issue users must upgrade to 3.2.0 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-34538.
Read more Data AnalyticsIn Mattermost Plugins versions <=2.3.1 high severity vulnerability CVE-2026-21388 was detected. This vulnerability allows authenticated attackers to cause memory exhaustion and denial of service via sending an oversized JSON payload to the /lifecycle webhook endpoint. To address this issue users must upgrade to 2.3.2.0 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21388.
Read more CommunicationIn Mattermost Plugin Legal Hold versions <=1.4.1 high severity vulnerability CVE-2026-3524 was detected. This vulnerability allows authenticated attackers to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints due to a failure to halt request processing after a failed authorization check. To address this issue users must upgrade to 1.1.5.0 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-3524.
Read more CommunicationIn MinIO versions from RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z high severity vulnerability CVE-2026-39414 was detected. This vulnerability allows authenticated attackers to cause an Out-of-Memory (OOM) crash and denial of service by uploading specially crafted CSV files without newline characters, which triggers unlimited memory allocation during S3 Select processing. To address this issue users must upgrade to MinIO AIStor RELEASE.2025-12-20T04-58-37Z version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-39414.
Read more StorageIn Sonatype Nexus Repository versions 3.0.0 through 3.90.2 medium severity vulnerability CVE-2026-3438 was detected. This vulnerability allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim’s browser through a specially crafted URL on describe pages, requiring user interaction. To address this issue, users must upgrade to the 3.91.0 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-3438.
Read more Developer ToolsIn Sonatype Nexus Repository versions 3.22.1 through 3.90.2 critical severity vulnerability CVE-2026-3199 was detected. This vulnerability allows authenticated attackers with task creation permissions to execute arbitrary code by bypassing the nexus.scripts.allowCreation security control via task property injection. To address this issue users must upgrade to 3.91.0 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-3199.
Read more Developer ToolsIn LiteLLM versions prior to 1.83.0 high severity vulnerability CVE-2026-35030 was detected. This vulnerability allows attackers to bypass authentication via an OIDC userinfo cache key collision by crafting a token whose first 20 characters match a legitimate user’s cached token. To address this issue users must upgrade to the 1.83.0 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-35030.
Read more Data Analytics