{"pagination":{"currentPage":1,"totalPages":124,"totalEntries":3096,"resultsPerPage":25},"vulnerabilities":[{"cveID":"CVE-2026-63261","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-63261","sourceIdentifier":"security@elastic.co","published":"2026-07-21T23:18:02.817","lastModified":"2026-07-21T23:18:02.817","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory and become unavailable to all users."}],"affected":[{"source":"security@elastic.co","affectedData":[{"vendor":"Elastic","product":"Kibana","defaultStatus":"unaffected","versions":[{"version":"8.0.0","lessThanOrEqual":"8.19.18","versionType":"semver","status":"affected"},{"version":"9.4.0","lessThanOrEqual":"9.4.3","versionType":"semver","status":"affected"},{"version":"9.0.0","lessThanOrEqual":"9.3.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@elastic.co","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@elastic.co","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"references":[{"url":"https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-72/388575","source":"security@elastic.co"}]}}},"_id":"CVE-2026-63261"},{"cveID":"CVE-2026-63260","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-63260","sourceIdentifier":"security@elastic.co","published":"2026-07-21T23:18:02.697","lastModified":"2026-07-21T23:18:02.697","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request payload. Processing this user-supplied input requires resource-intensive memory allocation that can exhaust the available heap memory in the Kibana process, causing it to crash and become unavailable to all users."}],"affected":[{"source":"security@elastic.co","affectedData":[{"vendor":"Elastic","product":"Kibana","defaultStatus":"unaffected","versions":[{"version":"9.0.0","lessThanOrEqual":"9.3.7","versionType":"semver","status":"affected"},{"version":"8.0.0","lessThanOrEqual":"8.19.18","versionType":"semver","status":"affected"},{"version":"9.4.0","lessThanOrEqual":"9.4.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@elastic.co","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@elastic.co","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"references":[{"url":"https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-71/388574","source":"security@elastic.co"}]}}},"_id":"CVE-2026-63260"},{"cveID":"CVE-2026-63259","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-63259","sourceIdentifier":"security@elastic.co","published":"2026-07-21T23:18:02.580","lastModified":"2026-07-21T23:18:02.580","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access."}],"affected":[{"source":"security@elastic.co","affectedData":[{"vendor":"Elastic","product":"Kibana","defaultStatus":"unaffected","versions":[{"version":"9.4.0","lessThanOrEqual":"9.4.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@elastic.co","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"security@elastic.co","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://discuss.elastic.co/t/kibana-9-4-4-security-update-esa-2026-70/388573","source":"security@elastic.co"}]}}},"_id":"CVE-2026-63259"},{"cveID":"CVE-2026-63145","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-63145","sourceIdentifier":"security@elastic.co","published":"2026-07-21T23:18:02.460","lastModified":"2026-07-21T23:18:02.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1).\n\nA vulnerability exists in Kibana's Machine Learning functionality where a Machine Learning management endpoint performs an insufficient authorization check. The endpoint validates only a coarse privilege level but does not verify that the requesting user has access to the specific Machine Learning job or notification resources provided in the request. As a result, a low-privileged user with Machine Learning access in any Kibana space can manipulate Machine Learning audit and notification records for arbitrary jobs—including jobs in other spaces or belonging to other users—by leveraging Kibana's internally elevated credentials to write to restricted Machine Learning system indices that the user cannot access directly."}],"affected":[{"source":"security@elastic.co","affectedData":[{"vendor":"Elastic","product":"Kibana","defaultStatus":"unaffected","versions":[{"version":"9.4.0","lessThanOrEqual":"9.4.3","versionType":"semver","status":"affected"},{"version":"9.0.0","lessThanOrEqual":"9.3.7","versionType":"semver","status":"affected"},{"version":"8.0.0","lessThanOrEqual":"8.19.18","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@elastic.co","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"security@elastic.co","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-69/388572","source":"security@elastic.co"}]}}},"_id":"CVE-2026-63145"},{"cveID":"CVE-2026-63144","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-63144","sourceIdentifier":"security@elastic.co","published":"2026-07-21T23:18:02.343","lastModified":"2026-07-21T23:18:02.343","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch query evaluation component, causing a fatal error that terminates the affected node. In single-node deployments, this results in complete service outage; in multi-node clusters, it causes repeated node restarts and sustained availability degradation."}],"affected":[{"source":"security@elastic.co","affectedData":[{"vendor":"Elastic","product":"Elasticsearch","defaultStatus":"unaffected","versions":[{"version":"9.4.0","lessThanOrEqual":"9.4.3","versionType":"semver","status":"affected"},{"version":"9.3.0","lessThanOrEqual":"9.3.7","versionType":"semver","status":"affected"},{"version":"8.19.0","lessThanOrEqual":"8.19.18","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@elastic.co","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@elastic.co","type":"Secondary","description":[{"lang":"en","value":"CWE-674"}]}],"references":[{"url":"https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-security-update-esa-2026-68/388571","source":"security@elastic.co"}]}}},"_id":"CVE-2026-63144"},{"cveID":"CVE-2026-63143","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-63143","sourceIdentifier":"security@elastic.co","published":"2026-07-21T23:18:02.230","lastModified":"2026-07-21T23:18:02.230","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access."}],"affected":[{"source":"security@elastic.co","affectedData":[{"vendor":"Elastic","product":"Kibana","defaultStatus":"unaffected","versions":[{"version":"9.4.0","lessThanOrEqual":"9.4.3","versionType":"semver","status":"affected"},{"version":"9.3.0","lessThanOrEqual":"9.3.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@elastic.co","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"security@elastic.co","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://discuss.elastic.co/t/kibana-9-3-8-9-4-4-security-update-esa-2026-67/388569","source":"security@elastic.co"}]}}},"_id":"CVE-2026-63143"},{"cveID":"CVE-2026-63142","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-63142","sourceIdentifier":"security@elastic.co","published":"2026-07-21T23:18:02.110","lastModified":"2026-07-21T23:18:02.110","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy."}],"affected":[{"source":"security@elastic.co","affectedData":[{"vendor":"Elastic","product":"Kibana","defaultStatus":"unaffected","versions":[{"version":"9.4.0","lessThanOrEqual":"9.4.3","versionType":"semver","status":"affected"},{"version":"8.0.0","lessThanOrEqual":"8.19.18","versionType":"semver","status":"affected"},{"version":"9.0.0","lessThanOrEqual":"9.3.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@elastic.co","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4}]},"weaknesses":[{"source":"security@elastic.co","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-66/388568","source":"security@elastic.co"}]}}},"_id":"CVE-2026-63142"},{"cveID":"CVE-2026-56820","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-56820","sourceIdentifier":"security-advisories@github.com","published":"2026-07-21T23:17:52.403","lastModified":"2026-07-21T23:17:52.403","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"netty","product":"netty","versions":[{"version":">= 4.2.0.Final, < 4.2.16.Final","status":"affected"},{"version":"< 4.1.136.Final","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-295"}]}],"references":[{"url":"https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","source":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","source":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","source":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","source":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/security/advisories/GHSA-272m-gcwp-mpwg","source":"security-advisories@github.com"}]}}},"_id":"CVE-2026-56820"},{"cveID":"CVE-2026-56819","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-56819","sourceIdentifier":"security-advisories@github.com","published":"2026-07-21T23:17:52.263","lastModified":"2026-07-21T23:17:52.263","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"netty","product":"netty","versions":[{"version":">= 4.2.0.Final, < 4.2.16.Final","status":"affected"},{"version":">= 4.1.0.Final, < 4.1.136.Final","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-400"},{"lang":"en","value":"CWE-401"}]}],"references":[{"url":"https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003bhttps://github.com/netty/netty/releases/tag/netty-4.2.16.Final","source":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","source":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","source":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","source":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972","source":"security-advisories@github.com"}]}}},"_id":"CVE-2026-56819"},{"cveID":"CVE-2026-56817","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-56817","sourceIdentifier":"security-advisories@github.com","published":"2026-07-21T23:17:52.127","lastModified":"2026-07-21T23:17:52.127","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"netty","product":"netty","versions":[{"version":">= 4.2.0.Final, < 4.2.16.Final","status":"affected"},{"version":">= 4.1.0.Final, < 4.1.136.Final","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-611"}]}],"references":[{"url":"https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","source":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","source":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","source":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","source":"security-advisories@github.com"},{"url":"https://github.com/netty/netty/security/advisories/GHSA-4qhr-g3c6-fcfx","source":"security-advisories@github.com"}]}}},"_id":"CVE-2026-56817"},{"cveID":"CVE-2026-16517","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16517","sourceIdentifier":"secalert@redhat.com","published":"2026-07-21T23:17:00.587","lastModified":"2026-07-21T23:17:00.587","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"libarchive","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"libarchive","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"libarchive","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"libarchive","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"libarchive","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"libarchive","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhcos","cpes":["cpe:/a:redhat:openshift:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":2.9,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.4,"impactScore":1.4}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Primary","description":[{"lang":"en","value":"CWE-190"}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-16517","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2505492","source":"secalert@redhat.com"}]}}},"_id":"CVE-2026-16517"},{"cveID":"CVE-2026-16486","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16486","sourceIdentifier":"cna@vuldb.com","published":"2026-07-21T23:17:00.403","lastModified":"2026-07-21T23:17:00.403","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"SourceCodester","product":"Class and Exam Timetabling System","cpes":["cpe:2.3:a:sourcecodester:class_and_exam_timetabling_system:*:*:*:*:*:*:*:*"],"versions":[{"version":"1.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"},{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://github.com/kurshidheba852-hub/My-cve-repository/issues/1","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-16486","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/859907","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/380944","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/380944/cti","source":"cna@vuldb.com"},{"url":"https://www.sourcecodester.com/","source":"cna@vuldb.com"}]}}},"_id":"CVE-2026-16486"},{"cveID":"CVE-2026-16485","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16485","sourceIdentifier":"cna@vuldb.com","published":"2026-07-21T23:17:00.153","lastModified":"2026-07-21T23:17:00.153","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"SourceCodester","product":"Class and Exam Timetabling System","cpes":["cpe:2.3:a:sourcecodester:class_and_exam_timetabling_system:*:*:*:*:*:*:*:*"],"versions":[{"version":"1.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"},{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://github.com/ashfaqsharif47-arch/Web-RCE/issues/1","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-16485","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/859906","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/380943","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/380943/cti","source":"cna@vuldb.com"},{"url":"https://www.sourcecodester.com/","source":"cna@vuldb.com"}]}}},"_id":"CVE-2026-16485"},{"cveID":"CVE-2026-16424","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16424","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-21T23:17:00.030","lastModified":"2026-07-21T23:17:00.030","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"150.0.7871.182","lessThan":"150.0.7871.182","versionType":"custom","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Primary","description":[{"lang":"en","value":"CWE-416"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/534858939","source":"chrome-cve-admin@google.com"}]}}},"_id":"CVE-2026-16424"},{"cveID":"CVE-2026-16423","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16423","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-21T23:16:59.923","lastModified":"2026-07-21T23:16:59.923","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"150.0.7871.182","lessThan":"150.0.7871.182","versionType":"custom","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Primary","description":[{"lang":"en","value":"CWE-416"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/534582496","source":"chrome-cve-admin@google.com"}]}}},"_id":"CVE-2026-16423"},{"cveID":"CVE-2026-16422","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16422","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-21T23:16:59.817","lastModified":"2026-07-21T23:16:59.817","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"150.0.7871.182","lessThan":"150.0.7871.182","versionType":"custom","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/533515002","source":"chrome-cve-admin@google.com"}]}}},"_id":"CVE-2026-16422"},{"cveID":"CVE-2026-16421","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16421","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-21T23:16:59.710","lastModified":"2026-07-21T23:16:59.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"150.0.7871.182","lessThan":"150.0.7871.182","versionType":"custom","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/528276487","source":"chrome-cve-admin@google.com"}]}}},"_id":"CVE-2026-16421"},{"cveID":"CVE-2026-16420","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16420","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-21T23:16:59.607","lastModified":"2026-07-21T23:16:59.607","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"150.0.7871.182","lessThan":"150.0.7871.182","versionType":"custom","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Primary","description":[{"lang":"en","value":"CWE-843"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/527930356","source":"chrome-cve-admin@google.com"}]}}},"_id":"CVE-2026-16420"},{"cveID":"CVE-2026-16419","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16419","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-21T23:16:59.503","lastModified":"2026-07-21T23:16:59.503","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"150.0.7871.182","lessThan":"150.0.7871.182","versionType":"custom","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/523435970","source":"chrome-cve-admin@google.com"}]}}},"_id":"CVE-2026-16419"},{"cveID":"CVE-2026-16418","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16418","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-21T23:16:59.400","lastModified":"2026-07-21T23:16:59.400","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"150.0.7871.182","lessThan":"150.0.7871.182","versionType":"custom","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Primary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/522125255","source":"chrome-cve-admin@google.com"}]}}},"_id":"CVE-2026-16418"},{"cveID":"CVE-2026-16417","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16417","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-21T23:16:59.287","lastModified":"2026-07-21T23:16:59.287","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"150.0.7871.182","lessThan":"150.0.7871.182","versionType":"custom","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Primary","description":[{"lang":"en","value":"CWE-457"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/521491024","source":"chrome-cve-admin@google.com"}]}}},"_id":"CVE-2026-16417"},{"cveID":"CVE-2026-16416","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16416","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-21T23:16:59.170","lastModified":"2026-07-21T23:16:59.170","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"150.0.7871.182","lessThan":"150.0.7871.182","versionType":"custom","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Primary","description":[{"lang":"en","value":"CWE-190"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/520172356","source":"chrome-cve-admin@google.com"}]}}},"_id":"CVE-2026-16416"},{"cveID":"CVE-2026-16415","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16415","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-21T23:16:59.053","lastModified":"2026-07-21T23:16:59.053","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"150.0.7871.182","lessThan":"150.0.7871.182","versionType":"custom","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/519244446","source":"chrome-cve-admin@google.com"}]}}},"_id":"CVE-2026-16415"},{"cveID":"CVE-2026-16414","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16414","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-21T23:16:58.943","lastModified":"2026-07-21T23:16:58.943","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"150.0.7871.182","lessThan":"150.0.7871.182","versionType":"custom","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/517651910","source":"chrome-cve-admin@google.com"}]}}},"_id":"CVE-2026-16414"},{"cveID":"CVE-2026-16413","namespaces":{"nvd_nist_gov":{"cve":{"id":"CVE-2026-16413","sourceIdentifier":"chrome-cve-admin@google.com","published":"2026-07-21T23:16:58.017","lastModified":"2026-07-21T23:16:58.017","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)"}],"affected":[{"source":"chrome-cve-admin@google.com","affectedData":[{"vendor":"Google","product":"Chrome","versions":[{"version":"150.0.7871.182","lessThan":"150.0.7871.182","versionType":"custom","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"chrome-cve-admin@google.com","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html","source":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/517359779","source":"chrome-cve-admin@google.com"}]}}},"_id":"CVE-2026-16413"}]}