DEV Community

#vulnerability

Discussions about specific security vulnerabilities and CVEs.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Closing the execution sink: defensive patterns after CVE-2026-100382

Closing the execution sink: defensive patterns after CVE-2026-100382

Comments
3 min read
Three JFrog Artifactory Flaws in One KEV Cycle: Authentication Failures in the Build Supply Chain

Three JFrog Artifactory Flaws in One KEV Cycle: Authentication Failures in the Build Supply Chain

Comments
3 min read
ZooKeeper Flaws Ripple Through Hadoop and Kafka Dependency Chains

ZooKeeper Flaws Ripple Through Hadoop and Kafka Dependency Chains

Comments
1 min read
Apache httpd 2.4.68 to 2.4.69: Upgrade Notes for the CVE-2026-63292 Fix and Companion Advisories

Apache httpd 2.4.68 to 2.4.69: Upgrade Notes for the CVE-2026-63292 Fix and Companion Advisories

Comments
2 min read
Citrix NetScaler ADC and Gateway: eight advisories, two under active exploitation (CVE-2026-88776)

Citrix NetScaler ADC and Gateway: eight advisories, two under active exploitation (CVE-2026-88776)

Comments
4 min read
Exposure Context for CVE-2026-96358: What 436,276 Drupal Fingerprints Mean

Exposure Context for CVE-2026-96358: What 436,276 Drupal Fingerprints Mean

Comments
2 min read
What full control of a reverse proxy console means after CVE-2026-107806

What full control of a reverse proxy console means after CVE-2026-107806

Comments 1
3 min read
SNI, Host headers and the limits of name-based virtual hosting: CVE-2026-102795 explained

SNI, Host headers and the limits of name-based virtual hosting: CVE-2026-102795 explained

Comments
2 min read
What CVE-2026-76266 shows about trusting installation content in package scripts

What CVE-2026-76266 shows about trusting installation content in package scripts

Comments
2 min read
CVE-2026-94545 Exploitability Deep Dive: Escaping, Native Parsing and the Non-PIE Node Build

CVE-2026-94545 Exploitability Deep Dive: Escaping, Native Parsing and the Non-PIE Node Build

Comments
2 min read
Drupal Webform XSS (CVE-2026-96367): what site builders need to check first

Drupal Webform XSS (CVE-2026-96367): what site builders need to check first

Comments
2 min read
SSH Rekey During Authentication: The Protocol Edge Case Behind CVE-2026-67279

SSH Rekey During Authentication: The Protocol Edge Case Behind CVE-2026-67279

Comments
3 min read
CVE-2026-96358: What Remote Exploitability Means for a Drupal Extension Flaw

CVE-2026-96358: What Remote Exploitability Means for a Drupal Extension Flaw

1
Comments
2 min read
Alluxio's S3 proxy skipped signature verification, and everyone was root

Alluxio's S3 proxy skipped signature verification, and everyone was root

Comments
3 min read
CVE-2026-105763 remediation runbook: patching Twenty CRM and rotating what leaked

CVE-2026-105763 remediation runbook: patching Twenty CRM and rotating what leaked

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.