Vulnfeed

Archives
Log in
Subscribe
July 29, 2026

[vulnfeed] 3 critical CVEs — 2026-07-29 00:00 UTC

vulnfeed Critical alert — 2026-07-29 03:47 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-54658CRITICAL
Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/
Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substit
CVSS 9.8
CVE-2026-62325CRITICAL
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so runnin
CVSS 9.1
CVE-2026-64863CRITICAL
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserv
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-d
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-07-29 04:00 UTC Older → [vulnfeed] 3 critical CVEs — 2026-07-28 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.