A security flaw has been found in the Erlang OTP software's built-in inets httpd web server module, categorized as an HTTP Request Smuggling vulnerability. This issue stems from how the server handles duplicate Content-Length headers (the part of a web request that tells the server how large the request's data is) that are sometimes included in ...
Continue reading
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and ...
Continue reading
PhpSpreadsheet is a popular tool many websites use to read and write spreadsheet files like Excel or CSV documents. A security flaw tracked as CVE-2026-34084 affects all versions of the tool up to 1.30.2, 2.1.14, 2.4.3, 3.10.3, and 5.5.0.The flaw only creates a risk if your site uses PhpSpreadsheet to load a spreadsheet file whose name comes ...
Continue reading
On July 20, 2026, MyCERT issued a security advisory for Microsoft SharePoint users, after new methods to exploit security flaws in the popular collaboration and file storage platform were discovered.If your website or business operations rely on Microsoft SharePoint, these newly identified exploits could create security risks for the data and ...
Continue reading