Announcements

Kestra Kestra OSS: Kestra OSS OS Command Injection Vulnerability

  • 5th September 2026

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-49869

Continue reading

Kludex Starlette: Kludex Starlette HTTP Request/Response Smuggling Vulnerability

  • 5th September 2026
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.Source: CISA ...
Continue reading

BerriAI LiteLLM: BerriAI LiteLLM Improper Authentication Vulnerability

  • 5th September 2026

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-59822

Continue reading

Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability

  • 5th September 2026
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.Source: CISA Known Exploited ...
Continue reading