|
791
|
2.2 |
LOW
Local
|
-
|
-
|
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json. A race condition in the file write path could briefly create or rewrite this …
New
|
CWE-367 CWE-732
Time-of-check Time-of-use (TOCTOU) Race Condition Incorrect Permission Assignment for Critical Resource
|
CVE-2026-54327
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
792
|
7.3 |
HIGH
Local
|
-
|
-
|
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directo…
New
|
CWE-379
Creation of Temporary File in Directory with Incorrect Permissions
|
CVE-2026-54328
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
793
|
4.4 |
MEDIUM
Local
|
-
|
-
|
Pi is a minimal terminal coding harness. Pi before 0.79.0 loaded project-local configuration and resources from a repository's .pi directory without first asking the user to trust that repository. Th…
New
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-54325
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
794
|
- |
|
-
|
-
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends …
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-50193
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
795
|
8.1 |
HIGH
Network
|
-
|
-
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeVali…
New
|
CWE-184 CWE-502
Incomplete Blacklist Deserialization of Untrusted Data
|
CVE-2026-54512
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
796
|
8.1 |
HIGH
Network
|
-
|
-
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.…
New
|
CWE-184
Incomplete Blacklist
|
CVE-2026-54513
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
797
|
5.3 |
MEDIUM
Network
|
-
|
-
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed I…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-54514
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
798
|
5.3 |
MEDIUM
Network
|
-
|
-
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextua…
New
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-54515
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
799
|
5.3 |
MEDIUM
Network
|
-
|
-
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() all…
New
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-54516
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
800
|
5.3 |
MEDIUM
Network
|
-
|
-
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBa…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-54517
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|