From Our Security Partners
CVE-2025-48431 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.
Information published.
CVE-2026-42151 Prometheus Azure AD remote write OAuth client secret exposed via config API
Information published.
CVE-2026-42154 Prometheus: remote read endpoint allows denial of service via crafted snappy payload
Information published.
CVE-2026-6210 Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash
Information published.
CVE-2026-39817 Invoking “go tool pack” does not sanitize output paths in cmd/go
Information published.
CVE-2026-8177 XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences
Information published.
CVE-2026-42501 Malicious module proxy can bypass checksum database in cmd/go
Information published.
CVE-2026-39819 Invoking “go bug” follows symlinks in predictable temporary filenames in cmd/go
Information published.