[vulnfeed] 2 critical CVEs — 2026-08-21 12:00 UTC
vulnfeed
Critical alert — 2026-08-21 13:24 UTC
2 new critical CVEs
in the last 5 hours — 2 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-77086CRITICAL
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, al
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequ
CVSS 9.4
CVE-2026-77776CRITICAL
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read d
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat complet
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: