These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,108 reserved CVEs with public mentions, ranked by all-time mention count.
Page 12 of 45
CVE-2026-95510 is an uninitialized-memory vulnerability in GNU Inetutils libinetutils' setsig() function, used by rlogin, rlogind, and telnetd. The function initializes signal masks but fails to initialize struct sigaction.sa_flags before OR-ing SA_RESTART into it. Residual stack data can therefore retain SA_RESTORER in sa_flags and leave sa_restorer as an uninitialized function pointer on architectures that honor application-supplied restorers. The flaw has existed since GNU Inetutils 1.9. Telnetd crashes triggered during SIGCHLD handling have been reproducibly observed; potential code execution through manipulation or use of the uninitialized signal-restorer pointer has not been confirmed.
CVE-2026-95510First seen Sep 26, 2026
First seen Aug 30, 2026
CVE-2026-92709 concerns rsyslog's omfile dynaFile facility when a dynamic file-path template incorporates untrusted input as a path component without secure path handling. Crafted input can cause the rendered output path to traverse outside the administrator-intended logging directory. The available information does not identify affected rsyslog versions, a vulnerable function, or a vendor-fixed release.
CVE-2026-92709First seen Sep 24, 2026
CVE-2026-93402 is an authorization flaw in rsyslog's optional imdtls input module. When DTLS is configured with tls.authmode set to "name" or "fingerprint", the module does not terminate or reject an established DTLS session when the tls.permittedpeer identity check fails. It logs a warning but retains the session and forwards received DTLS records to the configured rsyslog ruleset.
CVE-2026-93402First seen Sep 24, 2026
CVE-2026-93403 is a stack-based buffer overflow in rsyslog's mmpstrucdata output module affecting versions before 8.2606.0. An unauthenticated remote sender can trigger the flaw by delivering a crafted RFC 5424 syslog message to an affected rsyslog instance.
CVE-2026-93403First seen Sep 24, 2026
CVE-2026-61627 is an error in libass handling of certain ASS subtitle files during wrapped-line measurement. Processing a crafted ASS subtitle can cause libass to crash and may permit arbitrary code execution. The affected Debian 12 packages include libass9 and libass-dev.
CVE-2026-61627First seen Sep 4, 2026
CVE-2026-84678 is a code-execution vulnerability in Red Hat Ansible Automation Controller. The GALAXY_TASK_ENV setting permits unfiltered dynamic-linker or interpreter-related environment variables to be supplied to a task environment. An attacker able to control this setting can influence process initialization or interpreter behavior and execute attacker-controlled code in the relevant execution context.
CVE-2026-84678First seen Sep 24, 2026
CVE-2026-95507 is an out-of-bounds read in libslirp's NC-SI OEM response handler. When processing a truncated NC-SI OEM Ethernet frame, the handler can read up to four bytes beyond the supplied packet length. The out-of-bounds data is reflected in a response delivered to the guest, exposing adjacent memory from the host process running libslirp.
CVE-2026-95507First seen Sep 23, 2026
CVE-2026-85495 is a pre-authentication global buffer overflow in pppd's construction of LCP Configure-NAK messages. A PPP link peer can supply repeated PAP-AUTHTYPE options that cause pppd to write beyond the fixed 1500-byte nak_buffer. The condition is reported to affect CHAP-only hardening configurations that reject PAP and EAP.
CVE-2026-85495First seen Sep 23, 2026
CVE-2026-62846First seen Sep 17, 2026
First seen Sep 17, 2026
CVE-2026-63792 is an authorization flaw in Gitea's CanReadWorkflowCrossRepo access-control function. The collaborative-owner authorization path permits cross-repository reads of reusable workflow files without determining whether the Actions run originated from a fork pull request. Consequently, an approved fork pull-request workflow run against one private repository can retrieve reusable workflow contents from another private repository that trusts the first repository's owner as a collaborative owner. The requested Git reference is attacker-controlled, although reads remain limited to configured workflow directories.
CVE-2026-63792First seen Sep 15, 2026
CVE-2026-56828 is an improper-authorization vulnerability in Shopper Framework v2.8.0 administrative Livewire components. Administrative state-changing operations use the read-oriented view_users permission instead of access_setting, and one role-deletion action lacks an authorization check. A user authorized only to view users can modify permissions assigned to a role, including granting their own role settings-administration privileges; create a verified account with an attacker-selected password and an administrator role; remove role permissions; or delete roles marked removable.
CVE-2026-56828First seen Sep 12, 2026
CVE-2026-45517First seen Sep 9, 2026
CVE-2026-45529First seen Sep 9, 2026
CVE-2026-49913First seen Sep 9, 2026
CVE-2026-59176 is a high-severity improper inclusion of functionality from an untrusted control sphere vulnerability in functype-mcp-server before version 1.4.4. The set_functype_version MCP tool accepts an unsanitized pnpm package-specifier as a version value, installs the resulting package under the functype alias, and dynamically imports its CLI module. An attacker can supply an alias, local-path, or remote package specifier that causes attacker-controlled package content to be imported and executed by the MCP server process.
CVE-2026-59176First seen Sep 10, 2026
CVE-2026-59158 is a high-severity insufficiently protected credentials vulnerability in nuxt-ollama and related packages before version 1.3.1. The module merges configured options, including an Ollama API key, into Nuxt public runtime configuration. That public configuration is serialized into server-side-rendered HTML and is therefore accessible to unauthenticated browser clients. Version 1.3.1 separates the API key from public configuration and retains it in private server-side runtime configuration.
CVE-2026-59158First seen Sep 10, 2026
CVE-2026-59172 is an arbitrary code execution vulnerability in the github.com/candid82/joker linter. When invoked with linting enabled, Joker loads and executes linter customization code from a repository-local configuration location. Consequently, linting an untrusted repository can execute attacker-controlled code in the context of the Joker process. Joker 1.8.2 changes this behavior so executable linter customizations are loaded only from the user’s home configuration directory.
CVE-2026-59172First seen Sep 10, 2026
CVE-2025-24979 is a server-side request forgery vulnerability in LF Edge eKuiper external-service registration and HTTP-invocation functionality. An authenticated, highly privileged party able to register external services or create rules through the management interface can supply destinations that cause the eKuiper host to make requests to unintended network resources, including internal, loopback, link-local, multicast, unspecified, and cloud-metadata endpoints.
CVE-2025-24979First seen Sep 10, 2026
CVE-2025-24978 is a stored/self cross-site scripting vulnerability in LF Edge eKuiper external-service creation and update functionality. An authenticated user with management API access can supply a crafted external-service name containing HTML or script content. In affected versions, the value may be rendered by the administrative interface without appropriate escaping, causing attacker-controlled script to execute in the browser of a user viewing the service entry. Version 2.4.0 introduces strict alphanumeric identifier validation through validate.ValidateID for external-service creation and update operations.
CVE-2025-24978First seen Sep 10, 2026
CVE-2026-79605 is an out-of-bounds memory-access vulnerability in Tapdisk, the userspace xen-blkback implementation used by the XAPI toolstack. Tapdisk does not enforce an upper bound on blkif->last_sect. A malicious guest can supply a value greater than 7, causing Tapdisk to read from or write beyond the mapped grant memory region. The flaw affects all Tapdisk versions.
CVE-2026-79605First seen Sep 9, 2026
CVE-2026-79606 is an out-of-bounds memory-corruption vulnerability in Xen Tapdisk, the userspace xen-blkback implementation used by the XAPI toolstack. Incorrect bounds checking of the gcopy_segs[] object permits a guest-controlled nr_segments value from 12 through 32 to write beyond the intended object and corrupt adjacent memory. All Tapdisk versions are affected.
CVE-2026-79606First seen Sep 9, 2026
First seen Aug 30, 2026
First seen Sep 7, 2026