In Traefik versions prior to v2.11.51, v3.6.22, and v3.7.6 a critical severity vulnerability CVE-2026-54763 was detected. This vulnerability allows attackers to bypass authentication by using underscore-variant header names. To address this issue, users should upgrade Traefik to version 2.11.51 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-54763.
Read more SecurityIn vLLM versions before 0.24.0 a high severity vulnerability CVE-2026-54234 was detected. This vulnerability allows a remote attacker to crash the engine worker, causing a denial of service. To address this issue, users should upgrade vLLM to version 0.24.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-54234.
Read more Machine LearningIn Terraform a high severity vulnerability CVE-2026-14468 was detected. This vulnerability allows an authenticated user to include files from outside the intended repository content in a module and then download them, potentially exposing sensitive files. To address this issue, users should upgrade Terraform to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-14468.
Read more Developer ToolsIn vLLM versions 0.22.0 to 0.23.0 a medium severity vulnerability CVE-2026-55646 was detected. This vulnerability allows an attacker to cause a denial of service through memory exhaustion by uploading an oversized audio file. To address this issue, users should upgrade vLLM to version 0.24.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-55646.
Read more Machine LearningIn Pillow component for Python versions prior to 12.3.0 a medium severity vulnerability CVE-2026-55798 was detected. This vulnerability allows an attacker to inject arbitrary commands. To address this issue, users should upgrade Pillow to version 12.3.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-55798.
Read more Application DevelopmentIn Notifications for Forms & WordPress Actions component for WordPress versions before 2.6 a high severity vulnerability CVE-2024-6228 was detected. This vulnerability allows authenticated users with subscriber-level access to include and execute arbitrary local PHP files. To address this issue, users should upgrade Notifications for Forms & WordPress Actions to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-6228.
Read more CMS