[vulnfeed] 4 critical CVEs — 2026-07-18 16:00 UTC
vulnfeed
Critical alert — 2026-07-18 17:28 UTC
4 new critical CVEs
in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-16117CRITICAL
Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the pr
Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but re
CVSS 10.0
CVE-2025-71392CRITICAL
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field na
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User with OWNER or EDITOR
CVSS 9.4
CVE-2026-9323CRITICAL
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.st
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Python's Mersenne Twiste
CVSS 9.2
CVE-2024-58366CRITICAL
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function w
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string seq
CVSS 9.0
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: