2026 CVE Vulnerabilities

60,149 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50573HIGH8.1pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package ...
CVE-2026-50021HIGH8.1pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification wh...
CVE-2026-50017MEDIUM6.5pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials...
CVE-2026-50016HIGH8.8pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package ...
CVE-2026-50015HIGH7.3pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs...
CVE-2026-50014HIGH7.3pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value ...
CVE-2026-49839HIGH7.1jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into inval...
CVE-2026-48995HIGH7.5pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarbal...
CVE-2026-47770MEDIUM5.5jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operato...
CVE-2026-11999HIGH7.5X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_...
CVE-2026-9800HIGH8.1A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorizati...
CVE-2026-9799MEDIUM4.6A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permissio...
CVE-2026-9705MEDIUM6.5A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registrati...
CVE-2026-9099HIGH7.7A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin RE...
CVE-2026-9086HIGH7.3A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` ...
CVE-2026-9083MEDIUM4.9A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submi...
CVE-2026-56123CRITICAL9.8socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5...
CVE-2026-55439MEDIUM5.5Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download end...
CVE-2026-55413CRITICAL9.4ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ...
CVE-2026-55412HIGH8.3ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ...
CVE-2026-55411MEDIUM6.8ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ...
CVE-2026-55092HIGH7.5Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image...
CVE-2026-54573MEDIUM5.3Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess fun...
CVE-2026-54448MEDIUM6.5Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker read...
CVE-2026-54040HIGH7.1LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/auth/2fa/b...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now