advisories.gitlab.com
Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-04-22.
| Date Added | Resource | Excerpt |
|---|---|---|
| 2026-04-22 2026 | CVE-2026-33154: Dynaconf RCE via Insecure Jinja Template EvaluationSSTI | CVE-2026-33154: Dynaconf RCE via Insecure Jinja Template Evaluation |
| 2026-04-22 2026 | CVE-2026-5807: HashiCorp Vault DoS via Unauthenticated Root Token GenerationSecrets | CVE-2026-5807: HashiCorp Vault DoS via Unauthenticated Root Token Generation |
| 2026-04-22 2026 | CVE-2026-3605: HashiCorp Vault KVv2 Metadata Policy Bypass (DoS)Secrets | CVE-2026-3605: HashiCorp Vault KVv2 Metadata Policy Bypass (DoS) |
| 2026-04-22 2026 | CVE-2025-64431: IDOR in ZITADEL Organization API Allows Cross-Tenant TamperingIDOR | CVE-2025-64431: IDOR in ZITADEL Organization API Allows Cross-Tenant Tampering |
| 2026-04-10 2026 | CVE-2026-27127: Craft CMS Cloud Metadata SSRF via DNS RebindingSSRF | CVE-2026-27127: Craft CMS Cloud Metadata SSRF via DNS Rebinding |
| 2026-04-10 2026 | CVE-2026-33728: dd-trace-java Unsafe Deserialization in RMIDeser | CVE-2026-33728: dd-trace-java Unsafe Deserialization in RMI |
| 2026-04-10 2026 | CVE-2026-33439: OpenAM Pre-Auth RCE via DeserializationDeser | CVE-2026-33439: OpenAM Pre-Auth RCE via Deserialization |
| 2026-04-10 2026 | DbGate Stored XSS to RCE in Electron (CVE-2026-34725)XSS | DbGate Stored XSS to RCE in Electron (CVE-2026-34725) |
| 2026-04-09 2026 | FastMCP SSRF & Path Traversal via OpenAPI Provider (CVE-2026-32871)SSRF | FastMCP SSRF & Path Traversal via OpenAPI Provider (CVE-2026-32871) |
| 2026-04-09 2026 | Docker Model Runner SSRF in OCI Registry (CVE-2026-33990)SSRF | Docker Model Runner SSRF in OCI Registry (CVE-2026-33990) |
| 2026-04-09 2026 | AVideo SSRF Protection Bypass via Extension Allowlist (CVE-2026-39370)SSRF | AVideo SSRF Protection Bypass via Extension Allowlist (CVE-2026-39370) |
| 2026-04-09 2026 | AVideo Stored SSRF via Live Restream Log Callback (CVE-2026-39368)SSRF | AVideo Stored SSRF via Live Restream Log Callback (CVE-2026-39368) |
| 2026-04-09 2026 | mcp-from-openapi SSRF via $ref Dereferencing (CVE-2026-39885)SSRF | mcp-from-openapi SSRF via $ref Dereferencing (CVE-2026-39885) |
| 2026-04-09 2026 | Directus SSRF Bypass via IPv4-Mapped IPv6 Addresses (CVE-2026-35409)SSRF | Directus SSRF Bypass via IPv4-Mapped IPv6 Addresses (CVE-2026-35409) |
| 2026-04-09 2026 | Payload CMS Authenticated SSRF via Upload (CVE-2026-34746)SSRF | Payload CMS Authenticated SSRF via Upload (CVE-2026-34746) |
| 2026-04-09 2026 | Ech0: Unauthenticated SSRF to Cloud Metadata (CVE-2026-35037)SSRF | Ech0: Unauthenticated SSRF to Cloud Metadata (CVE-2026-35037) |
| 2026-04-09 2026 | Craft CMS Cloud Metadata SSRF Bypass via IPv6 (CVE-2026-27129)SSRF | Craft CMS Cloud Metadata SSRF Bypass via IPv6 (CVE-2026-27129) |