On July 22, 2026, MyCERT released a security advisory flagging a vulnerability in Oracle E-Business Suite described as improper privilege management. For users of this business software, this type of flaw means the system may fail to correctly restrict what different user accounts can access, edit, or do.This could potentially allow unauthorized ...
Continue reading
A vulnerability known as HTTP Request Smuggling has been found in Erlang OTP's inets httpd module, a component used in some web server setups.
The issue comes from a mismatch in how the module handles duplicate "Content-Length" headers, which signal the length of an incoming web request's body to a server. The affected module uses the first of ...
Continue reading
A vulnerability has been identified in NGINX JavaScript that only impacts sites with specific configuration settings. The flaw affects setups where the js_fetch_proxy directive is set to use at least one NGINX variable that pulls data from user input (such as HTTP headers, URL parameters, or cookies) and also calls the ngx.fetch() function from ...
Continue reading
A security flaw has been identified in two specific versions of MariaDB, a popular open-source database software used by many websites to store data such as user information, site content, and order records. The affected versions are 3.3.18 and 3.4.8.Normally, developers use a standard tool called mysql_real_escape_string() to block SQL injection ...
Continue reading