6 of 26
ADVISORY
HIGH: starcitizenwiki/embedvideo — Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled
With $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute without sanitization. When given a malformed url or id, the src attribute can be escaped via double quotes, allowing for…
HIGH2d ago
ADVISORY
HIGH: langchain-nvidia-ai-endpoints — langchain-nvidia-ai-endpoints has local file disclosure through VLM image inputs
langchain-nvidia-ai-endpoints versions before 1.4.2 accepted local filesystem paths as image inputs for Vision Language Model (VLM) requests. If an application passed attacker-controlled image input to ChatNVIDIA or VLM reranking APIs, an attacker…
HIGH3d ago
ADVISORY
CRITICAL: suneditor — SunEditor: Critical XSS vulnerability - sanitizer bypass
SUNEDITOR v2.47.10 appears to allow JavaScript execution through crafted namespaced HTML elements. The sanitization logic does not fully remove executable event-handler attributes from certain custom/namespaced tags. As a result, an attacker may be…
CRITICAL3d ago
ADVISORY
HIGH: github.com/klever-io/klever-go — Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller
The VM built-in function KleverUpdateAccountPermission (registered always-active, creator.go:381-390 / core/vmconstants.go:234) rewrites an account's entire permission set. Its authorization check uses vmInput.RecipientAddr attacker-controlled…
HIGH4d ago
ADVISORY
HIGH: plug — Plug: quadratic-time decoding of nested query/body parameters enables denial of service
Plug's nested-parameter decoder (Plug.Conn.Query) parses URL-encoded keys in time quadratic in their bracket-nesting depth. Any unauthenticated remote attacker that can reach a Plug-based HTTP endpoint can pin a BEAM scheduler for minutes with a…
HIGH4d ago
ADVISORY
CRITICAL: github.com/openbao/openbao — OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
When running in the highly privileged recovery mode, OpenBao was vulnerable to a timing attack against the single recovery token. This allowed an attacker to extract the recovery token and use it to perform operations against the OpenBao instance,…
CRITICAL5d ago
6 of 18
STATUS
npm: Issues with npm package publish and private install
Sep 27 , 00:50 UTC Investigating - We are currently investigating this issue.
ONGOING14h ago
STATUS
Datadog: Users are unable to acknowledge, escalate, or resolve On-Call Pages
Sep 25 , 11:29 EDT Monitoring - We are monitoring the issue. Sep 25 , 11:23 EDT Identified - We have identified the issue with pages and are applying mitigations. Sep 25 , 11:17 EDT Update - We are investigating an issue with users unable to acknowled
MONITORING2d ago
STATUS
Supabase: Project Lifecycle Issues in eu-west-1
Sep 24 , 15:50 UTC Identified - We have isolated the scope of the problem to a specific upstream incident. We are working to address the upstream incident and determine mitigations. Sep 24 , 15:36 UTC Investigating - We are investigating project lifecycle…
ONGOING3d ago
STATUS
Netlify: Elevated CDN Errors
Sep 23 , 23:40 UTC Update - We have identified the cause of the elevated CDN errors and are applying mitigations across affected systems. Recovery is underway, though some requests may continue to fail during this process. Sep 23 , 23:26 UTC Identified -…
ONGOING4d ago
STATUS
Supabase: Supabase CLI CI workflow failures
Sep 23 , 22:36 UTC Identified - We've identified the cause and are working on a fix. Sep 23 , 21:58 UTC Investigating - We're seeing rate limiting issues causing Supabase CLI CI workflow failures
ONGOING4d ago
STATUS
GitHub: Incident across several services
Sep 23 , 20:26 UTC Update - We are preparing to deploy a change that will mitigate the impact. Sep 23 , 18:42 UTC Update - Continuing to investigate the lag that may be experienced in issue labels being accurately reflected in Projects. We are working on…
ONGOING4d ago
6 of 36
CHANGELOG
Agents can now set up your website’s security with Turnstile Spin
Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification.
CHANGELOG2d ago
CHANGELOG
USN-8819-2: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking; - Netfilter;…
CHANGELOG2d ago
RELEASE
containerd v2.4.1
Welcome to the v2.4.1 release of containerd! The first patch release for containerd 2.4 contains various fixes and updates including a security patch. Security Updates containerd CVE-2026-53493 Highlights Container Runtime Interface (CRI) Fix bug where…
RELEASE3d ago
RELEASE
Ruff 0.16.9
Release Notes Released on 2026-09-24. Preview features [ ruff ] Avoid false positives for overloaded division ( RUF069 ) ( #28309 ) Bug fixes [ flake8-bugbear ] Avoid false positives for calls with keyword arguments ( B009 , B010 , B043 ) (<a…
RELEASE3d ago
CHANGELOG
Vercel Connect now supports TanStack AI
Agents built with TanStack AI can now call OAuth-protected MCP servers through Vercel Connect, with no credentials for you to store or rotate. The new @vercel/connect/tanstack-ai subpath exports connectMCPTransport , which takes a TanStack transport config…
CHANGELOG4d ago
CHANGELOG
Microsoft is updating its author-signing certificate starting September 23, 2026
Starting September 23, 2026, Microsoft is updating the author-signing certificate used for NuGet packages. Customers using trusted signer policies or certificate fingerprint verification should add the new certificate as soon as possible. The post…
CHANGELOG4d ago
8 of 40
STATUS
Snowflake: INC20000239
Sep 27 , 03:16 UTC Resolved - Current status: We've coordinated with our third-party cloud platform to implement the fix for this issue, and we've monitored the environment to confirm that service was restored. If you experience additional issues or have…
RESOLVED3h ago
STATUS
Render: Observing service instability from our upstream provider AWS in Oregon region
Sep 27 , 03:01 UTC Resolved - This incident has been resolved. Sep 27 , 02:17 UTC Update - All services, except for the free web services tier, have recovered. We continue to monitor. Sep 27 , 01:36 UTC Monitoring - Our upstream provider has begun rec
RESOLVED3h ago
NEW REPO
14h ago
NEW REPO
17h ago
NEW REPO
22h ago
SATURDAY, SEP 262 items
DISCUSSION
1d ago
STATUS
Snowflake: INC20000237
Sep 26 , 00:20 UTC Resolved - Current status: We've implemented the fix for this issue and monitored the environment to confirm that service was restored. Most impact was resolved by 22:59 UTC, with the remaining backlog for scheduled and serverless task…
RESOLVED1d ago
FRIDAY, SEP 252 items
STATUS
OpenAI: Issues with Codex
Status: Resolved All impacted services have now fully recovered. Affected components Codex API (Operational) Codex Web (Operational) CLI (Operational) VS Code extension (Operational)
2d ago
STATUS
Render: Build and deploy failures in Oregon
Sep 25 , 18:38 UTC Resolved - Builds and deploys failed for a subset of services in Oregon. Services using a prebuilt Docker image and static sites were unaffected. Sep 25 , 18:26 UTC Investigating - We are currently investigating this issue.
RESOLVED2d ago
THURSDAY, SEP 243 items
STATUS
GitHub: Disruption with billing information updates
Sep 24 , 20:41 UTC Resolved - This incident has been resolved. Thank you for your patience and understanding as we addressed this issue. A detailed root cause analysis will be shared as soon as it is available. Sep 24 , 20:24 UTC Monitoring - The…
RESOLVED3d ago
STATUS
Supabase: Permission errors in the Supabase Dashboard
Sep 24 , 11:49 UTC Resolved - This incident has been resolved. Administrative operations in the Supabase Dashboard are completing as expected, and we have observed no further permission related errors following the fix. Sep 24 , 11:08 UTC Monitoring - We…
RESOLVED3d ago
WEDNESDAY, SEP 235 items
STATUS
HashiCorp Cloud: HCP Terraform Returning 404s
Status: Investigating We are aware of and investigating reports of degraded performance with HCP Terraform. Our team is working to identify and resolve the issue. We will post updates with more information as it becomes available. Affected components HCP…
4d ago
CHANGELOG
Local sandboxing in the GitHub Copilot app
Local sandboxing helps reduce the potential impact of unintended commands by limiting access to files, network resources, and credentials on your machine. In the GitHub Copilot app, you configure it… The post Local sandboxing in the GitHub Copilot app…
CHANGELOG4d ago
STATUS
Elastic Cloud: Degraded Performance: Cloud Provisioning Delays
Sep 23 , 14:04 UTC Investigating - We are currently experiencing delays in provisioning new cloud resources due to slowness with an external container image provider. This may result in delays when creating new deployments, scaling existing ones, or…
ONGOING4d ago
CHANGELOG
OpenAI extends cyber access to Ukraine for civilian defense
OpenAI is extending access to its Daybreak program to the Government of Ukraine to support the cyber defense of civilian infrastructure.
CHANGELOG4d ago
STATUS
Supabase: Storage search failing for restored projects
Sep 23 , 10:20 UTC Monitoring - A fix has been implemented for the affected tenants and we are monitoring the results. We will continue to monitor the situation and will provide further updates as more information becomes available. Sep 23 , 09:31 UTC…
MONITORING4d ago
TUESDAY, SEP 2211 items
RELEASE
Electron v42.11.7
Release Notes for v42.11.7 Fixes Fixed a spurious " sandboxedrenderer.bundle.js script failed to run" console error when DevTools attached to a sandboxed frame before its first navigation. #54175 (Also in 43 ) Fixed an "Inval
RELEASE5d ago
ADVISORY
HIGH: github.com/cloudreve/Cloudreve/v4 — Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service
Cloudreve v4 splits the storage-quota check (reading the user's used bytes and comparing them to MaxStorage) and the charge (incrementing users.storage) into two non-atomic steps in the PrepareUpload code path. This creates a Time-of-Check to…
HIGH5d ago
ADVISORY
HIGH: lightrag-hku — lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
LightRAG's native markdown parser downloads external images referenced by an uploaded markdown or textpack document. The only SSRF guard, validatedaddresses() in lightrag/parser/markdown/parser.py, resolves the image host and rejects it when the…
HIGH5d ago
NEW REPO
5d ago
STATUS
OpenAI: Increased error rate for Plus and Pro users.
Status: Resolved All impacted services have now fully recovered. Affected components Conversations (Operational)
5d ago
RELEASE
Next.js v16.3.6
This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse
RELEASE5d ago
ADVISORY
HIGH: @sync-in/server — Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`
Affected component: Sync-in Server v2.3.0, POST /api/auth/token (auth.controller.ts:50-55). Required attacker capability: Valid username and password for a 2FA-enabled account. Summary POST /api/auth/token authenticates with username and password only,…
HIGH5d ago
RELEASE
Laravel v13.33.0
[13.x] Drop restartsyscalls from pcntlsignal in Worker by @jackbayliss in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5463051077" data-permission-text="Title is private"…
RELEASE5d ago
CHANGELOG
USN-8661-5: Linux kernel (Raspberry Pi) vulnerabilities
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use…
CHANGELOG5d ago