2026 CVE Vulnerabilities

61,333 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6277MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 1...
CVE-2026-6269MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, a...
CVE-2026-53912MEDIUM5.1Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflo...
CVE-2026-53423MEDIUM5.9Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unaut...
CVE-2026-4764CRITICAL9.4A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform all...
CVE-2026-3553LOW3.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, an...
CVE-2026-1500MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, a...
CVE-2026-10733MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, an...
CVE-2026-10087HIGH8.7GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 1...
CVE-2026-5497HIGH7.5vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded f...
CVE-2026-53911MEDIUM6.3Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit ope...
CVE-2026-11850MEDIUM5An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_lda...
CVE-2026-53901HIGH8.7Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler a...
CVE-2026-41856HIGH7.5The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on...
CVE-2026-41700HIGH8.1Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacki...
CVE-2026-41699CRITICAL9.8Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An a...
CVE-2026-41001MEDIUM5.3Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's da...
CVE-2026-41000LOW3.7Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-ti...
CVE-2026-40999HIGH8.6When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections ...
CVE-2026-40998HIGH8.2Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed atta...
CVE-2026-40997MEDIUM5.3Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or dis...
CVE-2026-40996MEDIUM4.8Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for ...
CVE-2026-40995MEDIUM5.4X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped...
CVE-2026-40994HIGH8.2Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation di...
CVE-2026-40992MEDIUM5Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now