Security Feed
CVE-2026-86140 – libxml2 stack-based buffer overflow in `xmlSnprintfElements()` via `strcat`
libxml2 before 2.15.4 contains a stack-based buffer overflow in xmlSnprintfElements() (valid.c) due to unsafe strcat usage. The CVSS vector is AV:L/AC:L/PR:N/UI:N, indicating local attack surface with no privileges required; exploitation can corrupt memory and compromise confidentiality/integrity. Upgrade libxml2 to 2.15.4+ to remediate.
CVE-2026-85656 – Amazon Linux log4j-cve-2021-44228-hotpatch OS command injection allows root
OS command injection in Amazon Linux log4j-cve-2021-44228-hotpatch lets a local user run arbitrary commands as root by abusing a Java process whose executable path contains embedded newline characters. Affected: versions < 1.3-9.amzn2. Remediate by upgrading the package to 1.3-9.amzn2 or later per Amazon advisories.
aaif-goose goose recipe extensions and retry checks allow arbitrary command execution
goose executes arbitrary shell commands embedded in recipe stdio extensions and retry.checks without security inspection. Malicious recipes delivered over the network can bypass the recipe security scan (extensions/retry config not inspected) and run commands as the local user executing goose. Affected: `aaif-goose/goose
sift.js prototype pollution enables JavaScript execution via `$where` query operator
sift (pkg:npm/sift) `
Traefik authentication bypasses via digestAuth and TLS option conflict fallback
traefik 0 < 2.11.55 and `3.0.0
Google Agent Development Kit builder endpoint path traversal enables arbitrary file read
A path traversal in the google-adk builder endpoint lets an unauthenticated remote attacker read arbitrary files via a crafted file_path query parameter. Affected: Google Cloud Agent Development Kit (ADK) for Python >= 1.9.0, < 1.22.0 (1.9.0–1.21.0). Impact is high confidentiality loss through file disclosure. Upgrade to 1.22.0+.
Deep Threat Research
Metabase Instances Actively Exploited: Unauthenticated Admin Takeover via BI Layer Reset Password SQL Injection (CVE-2026-72898)

Keyv Supply Chain Compromise: An npm Worm That Takes Its Orders From an Ethereum Smart Contract

Mastra Supply Chain Compromise: easy-day-js Dropper Pulls a Cross-Platform RAT Into @mastra Installs








