These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,178 reserved CVEs with public mentions, ranked by all-time mention count.
Page 37 of 48
CVE-2026-11099First seen Jun 7, 2026
First seen Jul 30, 2026
CVE-2025-47100First seen Jul 30, 2026
CVE-2026-21543First seen Jul 30, 2026
CVE-2024-36223First seen Jul 30, 2026
CVE-2024-54052First seen Jul 30, 2026
CVE-2026-21544First seen Jul 30, 2026
CVE-2024-54033First seen Jul 30, 2026
CVE-2026-21538First seen Jul 30, 2026
CVE-2025-64610First seen Jul 30, 2026
CVE-2026-28574First seen Jul 30, 2026
CVE-2026-11053First seen Jun 7, 2026
CVE-2025-64860First seen Jul 30, 2026
CVE-2026-21546First seen Jul 30, 2026
CVE-2025-26447First seen Jul 30, 2026
CVE-2026-21539First seen Jul 30, 2026
CVE-2026-21542First seen Jul 30, 2026
CVE-2026-21545First seen Jul 30, 2026
CVE-2026-21540First seen Jul 30, 2026
CVE-2026-21547First seen Jul 30, 2026
CVE-2026-49446 is an authentication bypass vulnerability in Cosmos-Server affecting the Constellation tunnel path. The flaw allows forward-auth header smuggling through Cosmos identity headers, including user identity headers, during Constellation handling. As a result, attacker-supplied identity information can be accepted in a way that bypasses normal Cosmos authentication controls. The issue permits bypass of JWT-based login, password, and MFA protections, and can also defeat admin-only authorization checks on proxied backends when those backends trust Cosmos forward-auth headers for identity and access decisions.
CVE-2026-49446First seen Jul 29, 2026
CVE-2023-37465 is a cross-site request forgery vulnerability in the XWiki Discussion Extension component org.xwiki.contrib:discussions-server. The flaw allows an attacker to cause a victim's browser to submit a forged request to the application, resulting in deletion of discussion messages. The issue affects the server-side discussion functionality prior to version 2.0-rc-1.
CVE-2023-37465First seen Jul 28, 2026
CVE-2026-62280 is a reflected cross-site scripting vulnerability in the OpenAM OAuth2/OIDC consent flow affecting the WAP consent page. Attacker-controlled values supplied in an OAuth2 authorization request can be reflected into the generated HTML without proper output encoding or escaping. This allows malicious script content to be injected into the consent page and executed in the security context of the OpenAM origin when a victim visits a crafted authorization link. The issue is exposed through the OAuth2 authorize workflow when the WAP display mode is used.
CVE-2026-62280First seen Jul 26, 2026
CVE-2026-57497 is a denial-of-service vulnerability in webtransport-go caused by improper handling of unknown WebTransport capsules with large payloads. When the implementation encounters unrecognized capsules, it buffers their contents in memory rather than draining and discarding them. A malicious or misbehaving peer can exploit this behavior by sending crafted capsules with excessively large payloads, causing unbounded memory consumption in affected webtransport-go clients or servers.
CVE-2026-57497First seen Jul 25, 2026
CVE-2026-59766 is an access control flaw in Gitea caused by an incomplete fix for CVE-2026-20800. After a user's access to a private repository is revoked, the user can still retrieve information through the authenticated API endpoints that list starred repositories and personal tracked-time entries. Specifically, the /api/v1/user/starred endpoint can continue to disclose metadata for private repositories the user had previously starred, and the /api/v1/user/times endpoint can continue to disclose private issue titles associated with time entries previously logged by that user. Exposed information includes repository metadata such as repository objects, clone and SSH URLs, privacy status, issue titles, and issue state. Available information indicates that repository contents and issue comment bodies are not exposed.
CVE-2026-59766First seen Jul 22, 2026