Security Feed
Multiple CVEs – OpenSSL DTLS, X.509, QUIC and SSL_CTX flaws (heap leak, UAF, memory exhaustion, OOB)
OpenSSL addresses four issues: CVE-2026-84782: Retransmit of suspended WANT_WRITE can OOB-read and leak heap bytes as plaintext handshake data or crash. (Affects 1.0.2-4.0 fixed in 1.0.2zs / 1.1.1zj / 3.0.23 / 3.4.8 / 3.5.9 / 3.6.5 / 4.0.3).
CVE-2026-84783 : Extension-cache use-after-free on concurrent first use of the same trusted CA in multi-threaded TLS (Affects 4.0 fixed in 4.0.3).
CVE-2026-84784 : Unbounded RETIRE_CONNECTION_ID backlog lets a peer force ~400 MB allocation / DoS (Affects 3.4-4.0 fixed in 3.4.8 / 3.5.9 / 3.6.5 / 4.0.3).
CVE-2026-72897: OOB access after mid-handshake SSL_set_SSL_CTX() when the new context has more provider sigalgs (Affects 3.4-4.0 same fixes as CVE-2026-84784).
CVE-2026-102010 – libstdc++ binary heap erase_if use-after-free leads to DoS
Use-after-free in GCC libstdc++: calling erase_if on a binary-heap priority queue can reallocate storage without updating an internal entry pointer. An attacker who can trigger this code path can cause an application crash (DoS) and potential memory corruption. Affected include Red Hat gcc/gcc-toolset-* packages on RHEL 6-10. Apply Red Hat updates for gcc/toolsets to mitigate.
Multiple CVEs – PyJWT mixed-algorithm key confusion and JWKS redirect flaws enable JWT forgery and key substitution
PyJWT has multiple flaws enabling token forgery when apps allow both HMAC and asymmetric algs: CVE-2026-102268 accepts mutated public-key PEM as HMAC secret; CVE-2026-102271 accepts DER public key bytes; CVE-2026-102272 accepts UTF-8 BOM-prefixed public JWK; CVE-2026-102273 accepts public JWK containers. CVE-2026-102267 lets PyJWKClient follow attacker-influenced redirects, enabling key substitution/credential disclosure. Upgrade to 2.14.0 to mitigate.
CVE-2026-51996 – mcp-remote getServerUrlHash code injection enables unauthenticated remote RCE
geelen/mcp-remote 0.1.16–0.1.38 allows unauthenticated remote arbitrary code execution via code injection in src/lib/utils.ts within getServerUrlHash. An attacker can exploit the network-exposed service to run attacker-controlled code, impacting confidentiality/integrity/availability. Update to 0.1.38 or disabling external access to the service to mitigate.
CVE-2026-86950 – Apple CoreGraphics out-of-bounds write via crafted file enables arbitrary code execution
An out-of-bounds write in Apple OS file processing allows a maliciously crafted file to trigger memory corruption and achieve arbitrary code execution. Affected: `iOS/iPadOS
CVE-2026-93355 – LiteLLM weak JWT auth allows account takeover via unverified email fallback
LiteLLM JWT auth allows a valid IdP JWT to impersonate any user by using an email-based fallback lookup without checking email_verified. An attacker can supply an unverified email matching a victim to inherit roles (incl. proxy_admin) and overwrite the victim’s identity binding for persistent admin access to API keys and user management. Affected: `










