|
441
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume tha…
Update
|
CWE-125 CWE-416 CWE-787
Out-of-bounds Read Use After Free Out-of-bounds Write
|
CVE-2026-6785
|
2026-04-29 04:45 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
442
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…
Update
|
CWE-125 CWE-416 CWE-787
Out-of-bounds Read Use After Free Out-of-bounds Write
|
CVE-2026-6786
|
2026-04-29 04:45 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
443
|
9.9 |
CRITICAL
Network
|
apache
|
camel
|
The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExec…
New
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2026-40453
|
2026-04-29 04:43 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
444
|
7.8 |
HIGH
Local
|
apache
|
camel
|
The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilte…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40048
|
2026-04-29 04:43 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
445
|
8.8 |
HIGH
Network
|
apache
|
camel
|
The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. …
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40473
|
2026-04-29 04:43 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
446
|
9.8 |
CRITICAL
Network
|
apache
|
camel
|
JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() …
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40860
|
2026-04-29 04:42 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
447
|
9.4 |
CRITICAL
Network
|
apache
|
camel
|
The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOu…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-33454
|
2026-04-29 04:42 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
448
|
8.2 |
HIGH
Network
|
apache
|
camel
|
When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via c…
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-40022
|
2026-04-29 04:41 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
449
|
8.8 |
HIGH
Network
|
apache
|
camel
|
The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInput…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40858
|
2026-04-29 04:41 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
450
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows trusted-proxy callers without operator.read scope to access protected assistant-me…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-41908
|
2026-04-29 04:41 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|