These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,097 reserved CVEs with public mentions, ranked by all-time mention count.
Page 2 of 44
CVE-2026-82373 is a use-after-free vulnerability in the ZNC IRC bouncer’s module-unloading functionality. An unprivileged ZNC user able to trigger module unloading can cause the vulnerable object-lifetime condition. The documented consequence is denial of service.
CVE-2026-82373First seen Sep 13, 2026
CVE-2026-67418 is an input-validation vulnerability in RabbitMQ's MQTT 5.0 message handling. A PUBLISH message containing a property that is inapplicable to PUBLISH operations can cause RabbitMQ to disconnect subscribers whose subscriptions match the published topic, rather than isolating or rejecting the malformed publication appropriately.
CVE-2026-67418First seen Aug 19, 2026
First seen Mar 18, 2026
CVE-2024-31884 is an improper certificate validation flaw in Ceph's Pybind-related handling of SSL/TLS connections for mail functionality. The issue arises because no SSL context is passed to the Python constructors imaplib.IMAP4_SSL and smtplib.SMTP_SSL. As a result, the remote server's X.509 certificate is not correctly validated and Ceph may accept any certificate presented by a server. This breaks the trust guarantees expected from TLS and allows interception or spoofing of the mail server connection in transit.
CVE-2024-31884First seen Jan 21, 2026
CVE-2026-3865 is a path traversal vulnerability in the Kubernetes CSI Driver for SMB. The flaw is caused by insufficient validation of the attacker-controlled subDir component embedded in the PersistentVolume volumeHandle used by the SMB CSI driver. The driver treated the volume identifier as a composite string, parsed the subdirectory field from it, and used path-joining logic to construct filesystem paths for operations on the backing SMB share without ensuring the resolved path remained confined to the intended managed subdirectory. By supplying traversal sequences in the volumeHandle, an attacker with permission to create PersistentVolume objects could cause the driver to escape the designated storage boundary. The vulnerable behavior is particularly exposed during cleanup and deletion workflows, where the driver may operate on unintended directories on the SMB server. Affected versions are CSI Driver for SMB releases prior to v1.20.1.
CVE-2026-3865First seen Apr 11, 2026
CVE-2026-20140 is a high-severity local privilege escalation vulnerability affecting Splunk Enterprise for Windows. The flaw arises from unsafe DLL resolution during Splunk service startup, allowing DLL search-order hijacking. A low-privileged local attacker who can place a malicious DLL in a location that is searched during service initialization may cause the Splunk service to load attacker-controlled code. Because the service starts with elevated privileges on Windows, successful exploitation can result in execution as NT AUTHORITY\SYSTEM. The issue affects Windows deployments only and does not impact non-Windows installations. Reported affected versions include Splunk Enterprise for Windows 10.0.0 through 10.0.2, 9.4.0 through 9.4.7, 9.3.0 through 9.3.8, and 9.2.0 through 9.2.11.
CVE-2026-20140First seen Feb 20, 2026
CVE-2024-28080 is an authentication bypass vulnerability in Gitblit’s SSH service. The flaw is in Gitblit’s integration with Apache MINA SSHD, specifically its handling of multi-stage public-key authentication. During the initial public-key authentication stage, Gitblit’s SshKeyAuthenticator.authenticate method stores authenticated user state in the ServerSession-backed SshDaemonClient by calling client.setUser(user) and client.setKey(key) as soon as the supplied public key matches a configured key for the requested username, before proof-of-possession of the corresponding private key has been verified. If signature generation or verification does not complete successfully, the session can still retain that user state. Gitblit’s UsernamePasswordAuthenticator.authenticate method then returns success early when client.getUser() is not null, causing subsequent password authentication to succeed even with an arbitrary or empty password. As a result, an attacker can impersonate a user on the SSH transport without the victim’s private key or password, provided the attacker knows a valid username and one of that user’s configured public keys. The issue reportedly affects Gitblit versions prior to 1.10.0 with public-key SSH authentication enabled.
CVE-2024-28080First seen Mar 18, 2026
CVE-2026-3886 is an integer overflow vulnerability in QEMU's virtio-gpu driver, associated with calc_image_hostmem. Improper validation of user-supplied data can cause an integer overflow before buffer allocation. An attacker capable of executing low-privileged code in a guest system can exploit the flaw to execute arbitrary code in the context of the host system. The vulnerability was publicly disclosed on June 9, 2026.
CVE-2026-3886First seen Jun 9, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
First seen Oct 7, 2026
CVE-2026-59986 is an integer-overflow vulnerability in an internal bounds check in librabbitmq, a C-based AMQP client library. On 32-bit systems, the bounds-check arithmetic can overflow, allowing an out-of-bounds read that can cause information disclosure or denial of service. The affected function name and precise triggering input are not established.
CVE-2026-59986First seen Aug 18, 2026
CVE-2026-61547 is a heap-based buffer overflow in rabbitmq-c, as distributed in librabbitmq. The public amqp_send_frame() API improperly handles serialization of an oversized AMQP_FRAME_BODY, allowing an application-provided oversized body frame to cause a heap out-of-bounds write. The flaw can crash the affected process and corrupt memory.
CVE-2026-61547First seen Aug 18, 2026
CVE-2026-89085 is a heap-based buffer overflow in GNU Parted's FAT-handling code, specifically involving the _init_fats and fat_table_read functions. Affected distributions include Fedora, Ubuntu, Debian, and Amazon Linux systems using vulnerable Parted packages. The flaw is associated with processing FAT metadata.
CVE-2026-89085First seen Sep 15, 2026
CVE-2026-89088 is a heap-based buffer overflow in GNU Parted's duplicate_legacy_root_dir functionality. Fedora updates for Parted resolve the vulnerability alongside fixes for partition-number allocation, FAT metadata-triggered errors, and resize-related integer-overflow conditions.
CVE-2026-89088First seen Sep 15, 2026
CVE-2026-92162 is a path-traversal vulnerability in Flatpak DeployAppstream affecting Flatpak 1.18.0 and earlier. Insufficient validation of an architecture parameter allows a malicious local user in an active session, on a system with at least one configured OCI remote, to supply a crafted architecture name to the privileged flatpak-system-helper. The helper can then create a root-owned directory tree, lock file, and icons directory outside the intended root directory; the directory-tree contents are determined by the OCI remote.
CVE-2026-92162First seen Sep 22, 2026
First seen Sep 27, 2026
CVE-2026-85218 is a double stack overflow in BlueZ AVRCP ListPlayerAttributes response handling. The flaw is present in the avrcp_list_player_attributes_rsp and avrcp_get_current_player_value processing paths, where malformed AVRCP media-control data can corrupt stack memory.
CVE-2026-85218First seen Sep 4, 2026
CVE-2026-16633 is a high-severity client-side cross-site scripting vulnerability in Mozilla PDF.js, distributed through pdfjs-dist and inherited by integrations such as ngx-extended-pdf-viewer that bundle vulnerable PDF.js code. A crafted PDF containing malicious XFA content can exploit encoding and sanitization-bypass defects in the escapePDFName and encodeToXmlString routines. Improper zero-padding of escaped control characters and incorrect handling of certain BMP non-characters permit attacker-controlled markup or script to cross rendering boundaries. When processed by a vulnerable viewer, the payload executes JavaScript in the origin of the application embedding the viewer.
CVE-2026-16633First seen Aug 6, 2026
CVE-2026-39210 is a heap buffer overflow in FFmpeg’s TS demuxer. The flaw was reported as having been introduced in 2010. The vulnerability affects FFmpeg’s parsing of MPEG transport stream data within the demuxing path, where malformed attacker-controlled media input can trigger an out-of-bounds write on heap-allocated memory. As a memory corruption issue in a media parser, successful exploitation can lead to process instability and may create conditions for further exploitation depending on allocator behavior, surrounding memory layout, and runtime protections.
CVE-2026-39210First seen Jun 6, 2026
First seen Oct 7, 2026