2026 CVE Vulnerabilities

60,112 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56876HIGH8.6extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file contain...
CVE-2026-55448MEDIUM6.3mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credent...
CVE-2026-55441HIGH8.6mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config fil...
CVE-2026-54557MEDIUM5.5mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its inst...
CVE-2026-54341HIGH7.5Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload ...
CVE-2026-48743HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-48706HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9...
CVE-2026-48497HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-48044HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7...
CVE-2026-48042HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-47778MEDIUM4.4Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-47775MEDIUM6.8Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-47692MEDIUM4.3Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9...
CVE-2026-47221HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9...
CVE-2026-47207MEDIUM6.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9...
CVE-2026-47206LOW2.3Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Proto...
CVE-2026-47204HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9...
CVE-2026-33646CRITICAL9.6mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files ...
CVE-2026-57518HIGH8.8Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage ...
CVE-2026-57231HIGH7.5Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environ...
CVE-2026-56823MEDIUM5.4AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-56663HIGH8.5AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-55686MEDIUM5.3Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where...
CVE-2026-55677HIGH7.5Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decodi...
CVE-2026-54636CRITICAL9.9Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now