» Tag
cve
31 postsRsync 3.5.0 Patches 33 Security Flaws in Path and Daemon Handling
Rsync 3.5.0 closes 33 security vulnerabilities, mostly symlink-race path handling bugs in the daemon and client, with CVE IDs and regression tests.
TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
TP-Link's Kasa EC71 camera exposed precise GPS coordinates via a 6-year-old unauthenticated protocol flaw, plus a fleet-wide RSA key and MD5 password storage.
Cargo Symlink Flaw Disclosed as CVE-2026-5223
CVE-2026-5223: Cargo mishandled symlinks in third-party registry tarballs, risking cache overwrites; fixed in Rust 1.96.0.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comNew API integer overflow turns $0.10 balance into $16.9 trillion
CVE-2026-71479 lets one request overflow New API's billing math, turning a $0.10 balance into $16.9T. CVSS 9.1, fixed in v1.0.0-rc.18.
CVE-2026-69243 PoC: aiohttp Request Smuggling via Rejected WebSocket Upgrade
First public PoC for CVE-2026-69243, an aiohttp request smuggling flaw via rejected WebSocket upgrades causing blind handler invocation behind Nginx.
CVE-Bench: A Sandbox Benchmark for LLM Agents Fixing Real CVEs
CVE-Bench is an open-source benchmark testing LLM agents' ability to fix real Python CVEs inside sandboxed Docker containers.
Linux Kernel UDP Corking Flaw Enables Local Privilege Escalation
Two Linux kernel CVEs (2026-53362, 2026-53366) expose a heap OOB write via UDP MSG_SPLICE_PAGES corking, enabling local privilege escalation.
AI Uncovers 15-Year-Old Root Vulnerability in Linux Kernel
GhostLock (CVE-2026-43499): AI tool VEGA found a 15-year-old use-after-free root exploit in Linux kernel futex code. What engineers need to patch now.
Januscape: 16-Year-Old UAF in KVM Shadow MMU Crashes Hosts
CVE-2026-53359 (Januscape) is a 16-year-old UAF in KVM's shadow paging code enabling guest-to-host escape; the public PoC reliably panics the host, disrupting all co-located VMs.
Januscape: 16-Year-Old Critical Linux KVM Escape, PoC Public
CVE-2026-53359 (Januscape) is a critical Linux KVM guest-to-host escape in the shadow MMU, present since 2010; a public PoC causes host kernel panic.