A vulnerability labeled as problematic has been found in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandlers/AuthorizationRequestHandlerDecorator.java. Such manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-90820. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header Construction. This manipulation causes http response splitting.
This vulnerability is handled as CVE-2026-90819. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability categorized as problematic has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browser Network Configuration. The manipulation results in server-side request forgery.
This vulnerability is known as CVE-2026-90818. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The reported GitHub issue was closed automatically due to inactivity.
A vulnerability was found in Floodlight. It has been rated as problematic. This issue affects some unknown processing of the component Link. The manipulation leads to insufficient verification of data authenticity.
This vulnerability is traded as CVE-2025-45480. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in LibreNMS up to 1.65.0. It has been declared as critical. This vulnerability affects unknown code of the file ajax_table.php of the component API Endpoint. Executing a manipulation of the argument searchPhrase can lead to sql injection.
This vulnerability appears as CVE-2020-15875. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode GuardBreaker: Derailing AI-assisted malware analysis with a code comment DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive […]
A vulnerability was found in FFmpeg 8.0.x. It has been classified as problematic. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service.
This vulnerability is reported as CVE-2026-90816. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability was found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1 and classified as critical. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component Convolution Filter. Such manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2026-90815. The attack can be executed remotely. Additionally, an exploit exists.
It is suggested to upgrade the affected component.
A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.13 and classified as critical. Affected by this vulnerability is the function githubRequest of the file src/utils/github.ts of the component GitHub API Handler. This manipulation of the argument path causes server-side request forgery.
This vulnerability is registered as CVE-2026-90814. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability, which was classified as problematic, was found in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in incorrect behavior order: validate before canonicalize.
This vulnerability is cataloged as CVE-2026-90813. The attack may be launched remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability, which was classified as problematic, has been found in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation leads to incorrect privilege assignment.
This vulnerability is listed as CVE-2026-90812. The attack may be initiated remotely. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability classified as problematic was found in cosmicstack-labs mercury-agent up to 1.2.0. This affects the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Permission Manifest. Executing a manipulation can lead to information disclosure.
This vulnerability is tracked as CVE-2026-90811. The attack is restricted to local execution. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.