Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
Bitnami VulnDB is not individually searchable yet β the search will cover the sources available on the search page.
| ID | Description | Published | Updated |
|---|---|---|---|
| bit-parse-2026-100632 | Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery | 2026-10-01T10:36:21.879Z | 2026-10-01T10:55:19.103Z |
| bit-parse-2026-100631 | Parse Server 9.0.0 Unauthenticated Installation Deletion via Operator Injection | 2026-10-01T10:36:20.756Z | 2026-10-01T10:55:19.103Z |
| bit-tomcat-2026-87022 | Apache Tomcat: WebSocket message smuggling with per-message-deflate | 2026-10-01T09:36:37.109Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-86350 | Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request header mix-up | 2026-10-01T09:36:35.863Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-86248 | Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled | 2026-10-01T09:36:34.620Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-79677 | Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout | 2026-10-01T09:36:33.350Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-78437 | Apache Tomcat: HTTP/2 DoS via malformed request | 2026-10-01T09:36:32.198Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-78383 | Apache Tomcat: AJP DoS via missing request body | 2026-10-01T09:36:30.969Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-77791 | Apache Tomcat: DoS via busy wait during WebSocket close | 2026-10-01T09:36:29.754Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-77762 | Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request | 2026-10-01T09:36:28.552Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-77756 | Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests | 2026-10-01T09:36:27.286Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-76183 | Apache Tomcat: Bypass of security constraints for WebSocket endpoints | 2026-10-01T09:36:26.067Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-75973 | Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured | 2026-10-01T09:36:24.843Z | 2026-10-01T09:55:18.588Z |
| bit-tomcat-2026-73581 | Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore | 2026-10-01T09:36:23.598Z | 2026-10-01T09:55:18.588Z |
| bit-php-2026-93682 | Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header | 2026-10-01T09:34:13.249Z | 2026-10-01T09:55:18.588Z |
| bit-php-2026-92842 | OOB read / info leak in convert.* stream filters when line-break-chars contains NUL | 2026-10-01T09:34:11.972Z | 2026-10-01T09:55:18.588Z |
| bit-php-2026-91769 | TLS Hostname Verification Falls Back to CN After SAN Mismatch | 2026-10-01T09:34:10.596Z | 2026-10-01T09:55:18.588Z |
| bit-php-2026-91768 | IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes) | 2026-10-01T09:34:09.436Z | 2026-10-01T09:55:18.588Z |
| bit-php-2026-91767 | Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN | 2026-10-01T09:34:08.275Z | 2026-10-01T09:55:18.588Z |
| bit-php-2026-91766 | Cross-origin credential leak in HTTP stream wrapper redirects | 2026-10-01T09:34:07.123Z | 2026-10-01T09:55:18.588Z |
| bit-php-2026-91765 | SOAP: Unbounded Recursion in Server-Side cleanup_xml_node | 2026-10-01T09:34:06.018Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67421 | RabbitMQ: Stored HTML Injection in RabbitMQ Management OAuth Error Handling | 2026-10-01T09:34:00.722Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67420 | RabbitMQ OAuth credential refresh retains revoked runtime tags | 2026-10-01T09:33:59.215Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67419 | RabbitMQ: Consecutive topic wildcards cause combinatorial routing work | 2026-10-01T09:33:57.784Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67415 | RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Service | 2026-10-01T09:33:56.453Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67413 | RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an Unbounded LIKE Regular Expression | 2026-10-01T09:33:55.170Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67412 | RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message access | 2026-10-01T09:33:53.667Z | 2026-10-01T09:55:18.588Z |
| bit-php-2026-6103 | Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection | 2026-10-01T09:33:52.290Z | 2026-10-01T09:55:18.588Z |
| bit-rabbitmq-2026-67411 | RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypass | 2026-10-01T09:33:52.137Z | 2026-10-01T09:55:18.588Z |
| bit-php-2026-17545 | PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS | 2026-10-01T09:33:50.951Z | 2026-10-01T09:55:18.588Z |