Vulnfeed

Archives
Log in
Subscribe
July 18, 2026

[vulnfeed] 4 critical CVEs — 2026-07-18 16:00 UTC

vulnfeed Critical alert — 2026-07-18 17:28 UTC
4 new critical CVEs in the last 5 hours — 4 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-16117CRITICAL
Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the pr
Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but re
CVSS 10.0
CVE-2025-71392CRITICAL
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field na
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User with OWNER or EDITOR
CVSS 9.4
CVE-2026-9323CRITICAL
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.st
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Python's Mersenne Twiste
CVSS 9.2
CVE-2024-58366CRITICAL
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function w
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string seq
CVSS 9.0

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 1 critical CVE — 2026-07-20 04:00 UTC Older → [vulnfeed] 1 critical CVE — 2026-07-18 12:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.