[vulnfeed] 3 critical CVEs — 2026-07-29 00:00 UTC
vulnfeed
Critical alert — 2026-07-29 03:47 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-54658CRITICAL
Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/
Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substit
CVSS 9.8
CVE-2026-62325CRITICAL
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so runnin
CVSS 9.1
CVE-2026-64863CRITICAL
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserv
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-d
CVSS 9.1
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: