These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,097 reserved CVEs with public mentions, ranked by all-time mention count.
Page 44 of 44
OpenAM Community Edition contains an unauthenticated authentication bypass in its RADIUS authentication module. The flaw allows an attacker to spoof a RADIUS Access-Accept response, causing OpenAM to treat the authentication as successful and create a valid session for an arbitrary RADIUS username. Based on the available information, exploitation does not require knowledge of the RADIUS shared secret and results in successful impersonation of a RADIUS-mapped user.
CVE-2026-46560First seen Jun 26, 2026
CVE-2026-45049 is an information exposure vulnerability in OpenAM Community Edition affecting the CDSSO CDCServlet component used in cross-domain single sign-on flows. Under affected configurations, the servlet can be abused so that a logged-in user's raw OpenAM session token is included in a POST request to an attacker-controlled URL. This exposes a bearer-style session artifact outside the intended trust boundary. Based on the available information, exploitation requires inducing an authenticated victim to visit a crafted URL and is relevant to deployments with CDSSO enabled, particularly where the non-default protective configuration is absent.
CVE-2026-45049First seen Jun 24, 2026
CVE-2026-44179 is a remote code execution vulnerability in xwiki-pro-macros affecting the excerpt-include macro. According to the provided advisory, the issue is caused by improper escaping of the included page title combined with execution of excerpt content with the macro's rights. This allows attacker-controlled content or parameters associated with the included page/excerpt processing path to be interpreted in a way that results in server-side code execution within the XWiki installation.
CVE-2026-44179First seen Jun 23, 2026
NL Portal Backend Libraries contain unauthenticated GraphQL form-definition resolvers that accept a caller-supplied Objecten-API URL and cause the backend to fetch that URL on the configured Objecten-API host while forwarding a privileged Objecten-API token. This creates a constrained server-side request forgery condition combined with missing authorization on the resolver. According to the provided advisory, affected functionality includes `getFormDefinitionByObjectenApiUrl` and deprecated `getFormDefinitionById`. The issue is constrained because outbound requests are limited to the configured Objecten-API host, and arbitrary object reads are further limited by typed deserialization, but an attacker can still influence the request target on that host and induce authenticated backend requests.
CVE-2026-55414First seen Jun 20, 2026
CVE-2026-54711 is an information exposure vulnerability in PGHoard where database connection information, including the username and password sourced from .pgpass, is written to debug-level logs. The issue results in sensitive credential material being recorded in log output during normal debugging or verbose operation, creating a secondary disclosure channel for secrets that should not be logged.
CVE-2026-54711First seen Jun 19, 2026
CVE-2026-54683 is an authorization flaw in NL Portal Backend Libraries documenten-api caused by an incomplete fix for CVE-2026-49463. In affected versions, any authenticated user could retrieve document contents through the REST endpoint GET /api/documentapi/*/document/*/content or through the GraphQL getDocumentContent query without a per-document authorization check. As a result, access control was enforced only at the authentication level, not at the individual document level, allowing users to access documents outside their permitted scope if they knew or could obtain a target document identifier. The issue was fully resolved in version 3.0.3.
CVE-2026-54683First seen Jun 19, 2026
SwiftNIO contains an out-of-bounds memory corruption vulnerability in ByteBuffer index and length handling. According to the provided advisory, affected helper functions perform unsafe UInt32(truncatingIfNeeded:) conversions on attacker-influenced index, offset, or length values. When values larger than UInt32.max are supplied, truncation can wrap the value and cause incorrect buffer position or size calculations, leading to out-of-bounds writes or reads and corruption of buffer contents or outbound packets.
CVE-2026-43671First seen Jun 13, 2026
CVE-2014-5244 is a denial-of-service vulnerability in the Symfony HttpFoundation component. The issue is triggered when Request::getHost() performs hostname validation on a maliciously long HTTP Host header. Processing an arbitrarily long hostname causes excessive computation during validation, allowing an attacker to consume application resources with crafted requests. The affected branches include Symfony HttpFoundation / Symfony 2.0.x, 2.1.x, 2.2.x, and vulnerable releases prior to the fixed versions in the maintained branches.
CVE-2014-5244First seen Jun 4, 2026
SwiftNIO contains a CRLF injection vulnerability in outbound HTTP/1.1 request and response start line components caused by insufficient validation in NIOHTTPRequestHeadersValidator and NIOHTTPResponseHeadersValidator. According to the provided advisory, validation was missing or inadequate for request URIs, custom HTTP methods, and response reason phrases, allowing attacker-controlled carriage return and line feed characters to be injected into HTTP/1.1 start lines. This can corrupt HTTP message framing and enable downstream protocol interpretation issues.
CVE-2026-28970First seen Jun 13, 2026
CVE-2025-30081 is a cross-site scripting (XSS) vulnerability in the Clickstorm SEO extension for TYPO3. According to the provided advisory, the flaw allows a logged-in TYPO3 backend user to inject improperly encoded input into HTML output rendered in the TYPO3 backend. The issue stems from insufficient output encoding of user-controlled input before it is included in backend HTML, enabling script-capable content to be executed in another user's browser within the backend context.
CVE-2025-30081First seen Jun 4, 2026
SwiftNIO's NIOHTTP1 HTTPDecoder accepts unbounded HTTP/1 header blocks. When processing HTTP/1 requests or responses, the decoder can accumulate header data without sufficient limits, allowing a remote peer to send excessively large or numerous headers. This can exhaust memory in applications using NIOHTTP1 and, in some downstream frameworks, may also trigger a process crash when framework-level header count limits are exceeded after the decoder has already accumulated the data.
CVE-2026-28980First seen Jun 13, 2026
CVE-2026-28975 affects swift-nio-extras in the NIOHTTPRequestDecompressor component. When decompression protection is configured using the .ratio(N) limit, the implementation can be bypassed by an attacker supplying a falsified inflated Content-Length header. The vulnerable logic relies on the header-supplied Content-Length value when enforcing the decompression ratio limit, rather than tracking the actual compressed bytes received. As a result, a highly compressed request body can be accepted and decompressed without the intended protection being applied.
CVE-2026-28975First seen Jun 13, 2026
A configuration-validation flaw in the Radius Kubernetes controller allows a tampered Deployment annotation, radapp.io/status, to reference a container resource outside the current tenant or namespace. When the controller processes the manipulated annotation, it can issue deletion of the referenced Radius-managed container resource without properly validating tenant or namespace ownership. In multi-tenant Radius installations, this creates a cross-tenant authorization failure where one tenant's Deployment metadata can influence deletion of another tenant's resource. The issue is described as affecting deletion logic tied to controller handling of annotated Deployment state.
CVE-2026-53999First seen Jun 13, 2026
CVE-2023-32198 is an improper certificate validation vulnerability in Steve. During TLS connections, Steve does not verify the remote server certificate by default, contrary to expected Go TLS certificate validation behavior. This allows a malicious intermediary to present an untrusted or spoofed certificate without being rejected, enabling interception and modification of traffic between Steve and the remote service. In Rancher deployments, the issue is particularly relevant under specific configuration conditions involving remote UI content retrieval.
CVE-2023-32198First seen Jun 4, 2026
CVE-2025-30083 is a cross-site scripting vulnerability in the codingms/additional-tca extension for TYPO3. According to the provided advisory, improperly encoded user input can be used by an authenticated TYPO3 backend user to create malicious output in an HTML context within the TYPO3 backend. The issue is therefore an authenticated backend-context XSS caused by insufficient output encoding of user-controlled data.
CVE-2025-30083First seen Jun 4, 2026
CVE-2015-2309 affects the Symfony HttpFoundation Request class. When at least one trusted proxy is configured, unsafe request-handling methods can incorrectly trust client-supplied HTTP header values. As a result, header-derived properties exposed by methods such as getPort(), isSecure(), getHost(), and getClientIps() may be influenced by attacker-controlled input rather than only by values inserted by trusted infrastructure. The issue is specifically tied to proxy trust handling in deployments that rely on forwarded headers to reconstruct the original client request context.
CVE-2015-2309First seen Jun 4, 2026
CVE-2014-4931 is a code injection vulnerability in Symfony FrameworkBundle's translation caching mechanism. According to the provided advisory context, attacker-controlled locale values, such as unsanitized _locale parameters supplied via URLs, can be written into generated cache files. If those locale values are not properly sanitized before reaching the translation caching logic, an attacker can inject arbitrary PHP code into the cache content, which may then be executed by the application.
CVE-2014-4931First seen Jun 4, 2026
CVE-2013-7035 is a cross-site scripting vulnerability in React affecting 0.5.x before 0.5.2 and 0.4.x before 0.4.2. According to the provided advisory, the issue is caused by improper sanitization of input used to create keys. If an application derives a React key from attacker-controlled input, the unsanitized value can be incorporated in a way that enables script execution in the victim's browser context.
CVE-2013-7035First seen Jun 4, 2026
CVE-2014-6061 is an authentication-related flaw in the Symfony HttpFoundation component affecting applications that rely on HTTP Basic or Digest authentication. The vulnerability stems from improper parsing of the HTTP Authorization header by HttpFoundation in certain server configurations. As a result, authentication handling may be performed incorrectly when the framework processes malformed or ambiguously parsed Authorization header data. Based on the provided advisory, the issue was fixed in Symfony versions 2.3.19, 2.4.9, and 2.5.4, with a corresponding patch published in Symfony pull request #11829.
CVE-2014-6061First seen Jun 4, 2026
CVE-2024-22031 is a privilege escalation vulnerability in Rancher caused by improper handling of project identity across clusters when projects share the same object name. According to the provided advisory, a user with permission to create projects on one cluster can create a project using the same name as an existing project in another cluster and thereby gain access to the other project. The issue appears to stem from namespace or object-name collision behavior across clusters, allowing authorization boundaries between clusters to be bypassed when duplicate project names exist.
CVE-2024-22031First seen Jun 4, 2026
Symfony HttpKernel contains an access control flaw affecting deployments where Edge Side Includes (ESI) support is enabled behind a trusted proxy. In affected versions, clients can directly request fragment/ESI URLs, such as the fragment endpoint, instead of having those requests mediated exclusively by the trusted proxy as intended. This can expose protected fragment endpoints or allow invocation of internal fragment functionality that should only be reachable through proxy-driven fragment rendering.
CVE-2014-5245First seen Jun 4, 2026
CVE-2025-66475 is a critical signature wrapping vulnerability affecting OneLogin php-saml through its xmlseclibs dependency. Based on the provided advisory, the flaw is in XML signature validation handling and can be exploited in SAML processing, allowing a maliciously crafted signed XML/SAML message to bypass intended signature protections. The issue affects deployments using vulnerable php-saml releases that depend on an unpatched xmlseclibs version.
CVE-2025-66475First seen Jun 4, 2026