These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,201 reserved CVEs with public mentions, ranked by all-time mention count.
Page 27 of 49
First seen Jul 2, 2026
First seen Jul 2, 2026
First seen Jul 2, 2026
First seen Jul 2, 2026
First seen Jun 29, 2026
CVE-2023-50756First seen Jun 27, 2026
CVE-2026-48785 is an incorrect path matching vulnerability in Apptainer affecting the 'limit container paths' directive when Apptainer is used in setuid mode. Due to flawed path validation or matching logic, Apptainer can incorrectly treat similarly named sibling directories as matching an allowed path, allowing a container image to be executed from an unintended location. The issue weakens administrator-enforced restrictions intended to limit which filesystem paths may be used for container execution.
CVE-2026-48785First seen Jun 13, 2026
First seen Jun 26, 2026
First seen Jun 26, 2026
First seen Jun 26, 2026
First seen Jun 26, 2026
First seen Jun 26, 2026
First seen Jun 26, 2026
First seen Jun 24, 2026
First seen Jun 24, 2026
CVE-2026-8462 is an authenticated SQL injection vulnerability in OpenMeter affecting the meter creation path exposed via POST /api/v1/meters. According to the provided advisory context, user-controlled valueProperty and groupBy fields are incorporated into a ClickHouse query using unsafe string interpolation. The flaw allows attacker-supplied input to bypass or escape intended JSONPath validation and be executed as SQL in the backend query context. In affected shared-database deployments, this can expose data across tenant boundaries. The issue was fixed in OpenMeter version 1.0.0-beta.228.
CVE-2026-8462First seen Jun 5, 2026
CVE-2026-39043First seen Jun 21, 2026
CVE-2026-39044First seen Jun 21, 2026
dbt MCP Server contains an unauthenticated local OAuth helper endpoint exposed on 127.0.0.1:6785 that returns dbt Platform context data via GET /dbt_platform_context. According to the provided advisory, this response can include dbt Cloud access_token and refresh_token values. Because the endpoint lacks authentication/authorization, an attacker able to reach the local helper can retrieve these bearer tokens directly. The issue affects the local OAuth helper design rather than a memory corruption flaw: sensitive token-bearing context is exposed through an unauthenticated HTTP endpoint, and the advisory notes reachability may occur from a co-located local process or through DNS rebinding.
CVE-2026-55837First seen Jun 20, 2026
First seen Jun 18, 2026
First seen Jun 18, 2026
First seen Jun 18, 2026
First seen Jun 18, 2026
First seen Jun 18, 2026
First seen Jun 17, 2026