Articles
Newsflash
30 Jun 2026 DevOps
Argo Workflows: Security Restrictions Bypass via Incomplete Fix for CVE-2026-31892

In Argo Workflows versions prior to 3.7.14 and 4.0.5 a high severity vulnerability CVE-2026-42296 was detected. This vulnerability allows an authenticated user with create Workflow permissions to bypass templateReferencing: Strict security boundaries, potentially leading to privilege escalation. This occurs due to an incomplete fix for CVE-2026-31892, which fails to restrict critical pod spec overrides. As a result, an attacker can gain host network access, switch service accounts, override pod security contexts, add tolerations to schedule on control-plane nodes, or enable ServiceAccount token mounting. While external Kubernetes controls (like PodSecurity admission or OPA/Gatekeeper) might mitigate some impacts, clusters relying solely on Argo’s Strict mode are fully exposed. To address this issue, users should upgrade Argo Workflows to versions 3.7.14, 4.0.5, or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-42296.

Read more
Developer Tools
30 Jun 2026 DevOps
Backstage: Arbitrary Code Execution via MkDocs Hooks in TechDocs

In Backstage (@backstage/plugin-techdocs-node) versions prior to 1.13.11 and 1.14.1 a high severity vulnerability CVE-2026-25153 was detected. This vulnerability allows an attacker to execute arbitrary Python code on the TechDocs build server, leading to Remote Code Execution (RCE). This occurs when TechDocs is configured with runIn: local and a malicious actor modifies a repository’s mkdocs.yml file to include malicious MkDocs hooks. To address this issue, users should upgrade @backstage/plugin-techdocs-node to versions 1.13.11, 1.14.1, or later, which introduce an allowlist that strips unsupported configuration keys like hooks. Alternatively, users can mitigate the risk by configuring TechDocs with runIn: docker or using MkDocs versions prior to 1.4.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25153.

Read more
Developer Tools
30 Jun 2026 DevOps
GitBucket: Server-Side Request Forgery (SSRF) in Repository Creation

In GitBucket versions up to 4.46.1 a medium severity vulnerability CVE-2026-13540 was detected. This vulnerability allows a remote attacker to perform Server-Side Request Forgery (SSRF), potentially gaining unauthorized access to internal network resources. This occurs due to improper handling of the url argument within the Git.cloneRepository.setURI function in the src/main/scala/gitbucket/core/service/RepositoryCreationService.scala file. By supplying a maliciously crafted URL during repository cloning or creation, an attacker can coerce the server into making unintended network requests. A public exploit has been released, which heightens the risk of active attacks. To address this issue, users should apply the vendor-supplied patch (commit 487a9b980f56aa73b6a044b1e86a92eed5043215) or upgrade to a patched release 4.46.2 (or later). For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-13540.

Read more
Developer Tools
30 Jun 2026 DevOps
Appsmith: SSRF and Information Disclosure via Email Configuration Endpoint

In Appsmith versions prior to 1.99 a low severity vulnerability CVE-2026-49979 was detected. This vulnerability allows an attacker to perform Server-Side Request Forgery (SSRF), internal port scanning, and service banner enumeration. This occurs because the POST /api/v1/admin/send-test-email endpoint accepts user-controlled smtpHost and smtpPort parameters and establishes a raw JavaMail TCP connection without any IP validation. This completely bypasses the WebClientUtils.IP_CHECK_FILTER, which only applies to Spring WebClient HTTP requests. Furthermore, the endpoint returns the raw MailException.getMessage() verbatim in the API error response, leaking internal network details to the attacker. To address this issue, users should upgrade Appsmith to version 1.99 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-49979.

Read more
Application Development
30 Jun 2026 DevOps
Django: Denial of Service via URLField Unicode Normalization on Windows

In Django versions 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29 (with earlier unsupported versions potentially affected) a high severity vulnerability CVE-2026-25673 was detected. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) through resource exhaustion. This occurs because URLField.to_python() calls urllib.parse.urlsplit(), which performs NFKC Unicode normalization on Windows systems. This normalization process is disproportionately slow for certain Unicode characters. By submitting large URL inputs containing these specific characters, an attacker can severely degrade system performance or cause a crash. To address this issue, users should upgrade Django to versions 6.0.3, 5.2.12, 4.2.29, or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25673.

Read more
Application Development
29 Jun 2026 DevOps
Gogs: Cross-Tenant LFS Content Disclosure via Unverified OID Deduplication

In Gogs versions prior to 0.14.3 a high severity vulnerability CVE-2026-52812 was detected. This vulnerability allows an authenticated user with write access to one repository to access and download private Git LFS content from other repositories, leading to unauthorized cross-tenant information disclosure. This occurs because the Git LFS storage deduplicates content using only the Object ID (OID). The serveUpload function skips the upload process if a file with the claimed OID already exists on disk, and binds it to the user’s repository without verifying that the provided request body actually hashes to that OID. By claiming an OID that belongs to a private repository, an attacker can bypass authorization checks and download the original file bytes through their own repository’s download endpoint. To address this issue, users should upgrade Gogs to version 0.14.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-52812.

Read more
Developer Tools
Case Studies