Announcements

CVE-2026-23941 (matched: apache http server)

  • 26th July 2026
A security flaw called HTTP Request Smuggling has been found in the Erlang OTP inets httpd module, a component used to run web services. This vulnerability creates a mismatch in how web requests are interpreted that attackers could exploit to interfere with your website's normal operations. The issue occurs because the affected software does not ...
Continue reading

CVE-2026-8711 (matched: nginx)

  • 26th July 2026
A vulnerability has been identified in NGINX JavaScript that only affects websites configured to use the js_fetch_proxy setting tied to user-controlled parts of incoming requests (such as request headers, URL parameters, or cookies) and that also use the ngx.fetch() function in their NGINX JavaScript code.Unauthenticated attackers can exploit this ...
Continue reading

CVE-2026-44172 (matched: mariadb)

  • 26th July 2026
A security flaw has been identified in specific older versions of MariaDB, a widely used open-source database system that many websites rely on to store content, user account information, and other site data. The affected versions are 3.3.18 and 3.4.8.This flaw can enable SQL injection attacks, which allow unauthorized users to run unapproved ...
Continue reading

CVE-2026-24425 (matched: php)

  • 26th July 2026
A security flaw has been identified in Twig, a widely used tool for building dynamic PHP websites. The vulnerability impacts Twig versions 2.16.x and 3.9.0 through 3.25.x.When a site uses Twig's sandbox security feature enabled via a source policy (rather than turned on globally for all templates), attackers who have the ability to edit or upload ...
Continue reading