These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,178 reserved CVEs with public mentions, ranked by all-time mention count.
Page 48 of 48
Fleet does not properly validate the SSH server's host certificate/key during connection establishment. According to the advisory, when connecting through SSH and the target server is not already present in known_hosts, Fleet may automatically trust an unknown server certificate instead of requiring verified host key validation. This creates a trust-on-first-use failure condition that allows an attacker to impersonate the remote SSH server. The issue affects SSH connection security rather than endpoint authentication logic on the remote host itself.
CVE-2025-23390First seen Jun 4, 2026
Nuclio Dashboard contains a missing authorization flaw in project write paths. According to the provided advisory, any authenticated user can perform project modification or deletion operations without being a member of the target project because OPA authorization is not properly enforced for project write requests. The affected operations include project update via PUT /api/projects/{id} and project deletion via DELETE /api/projects. This results in an authorization bypass in a multi-tenant management plane and, in Kubernetes deployments, may also affect behavior backed by the NuclioProject CRD.
CVE-2026-45730First seen Jun 5, 2026
CVE-2025-66475 is a critical signature wrapping vulnerability affecting OneLogin php-saml through its xmlseclibs dependency. Based on the provided advisory, the flaw is in XML signature validation handling and can be exploited in SAML processing, allowing a maliciously crafted signed XML/SAML message to bypass intended signature protections. The issue affects deployments using vulnerable php-saml releases that depend on an unpatched xmlseclibs version.
CVE-2025-66475First seen Jun 4, 2026