These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,178 reserved CVEs with public mentions, ranked by all-time mention count.
Page 12 of 48
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
CVE-2026-63124 is an infinite-loop denial-of-service vulnerability in io.netty.incubator:netty-incubator-codec-bhttp affecting the Binary HTTP parsing logic in BinaryHttpParser and BinaryHttpDecoder. The flaw is triggered when parsing a known-length field section that ends exactly on a complete field-line boundary. Under that boundary condition, crafted Binary HTTP input can cause the parser to repeatedly iterate without making forward progress, resulting in a non-terminating parse loop. The same parser condition can also be reached through OHTTP after successful decryption of a protected payload.
CVE-2026-63124First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 21, 2026
First seen Aug 20, 2026
First seen Aug 20, 2026
First seen Aug 20, 2026