These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,101 reserved CVEs with public mentions, ranked by all-time mention count.
Page 6 of 45
CVE-2026-35330 is a vulnerability in libsimaka involving the processing of certain EAP-SIM/AKA attributes. According to the provided context, malformed or specially crafted attributes can trigger either an infinite loop or a heap-based buffer overflow during parsing or handling of EAP-SIM/AKA data. The heap corruption condition may potentially lead to remote code execution. Specific vulnerable functions, affected versions, and patch details are not available in the provided content.
CVE-2026-35330First seen Apr 22, 2026
First seen Jun 18, 2026
CVE-2026-45354 is a high-severity pre-authentication DSI protocol desynchronization vulnerability in Netatalk, an implementation of the Apple Filing Protocol (AFP). The issue affects Netatalk versions 1.5.0 through 4.4.2. Based on the available context, the flaw occurs in handling of the DSI protocol before authentication is completed, allowing protocol state to become desynchronized. No vulnerable function or code path is identified in the provided material.
CVE-2026-45354First seen May 15, 2026
CVE-2026-45356 is a high-severity integer underflow vulnerability in Netatalk's Spotlight RPC handling, specifically in a count decrement operation. The issue affects Netatalk versions 3.1.0 through 4.4.2. The available context identifies the flaw as occurring during Spotlight RPC count decrement processing, indicating that malformed or attacker-controlled RPC input can cause an integer value to wrap below zero, leading to unsafe subsequent memory handling or logic errors.
CVE-2026-45356First seen May 15, 2026
CVE-2026-45355 is a high-severity vulnerability in Netatalk affecting versions 3.1.0 through 4.4.2. The issue is described as an integer underflow that leads to a heap out-of-bounds read. Based on the available information, improper handling of a length, count, or similar arithmetic value causes an underflow condition, which subsequently results in reads beyond the bounds of an allocated heap buffer during processing of attacker-supplied data.
CVE-2026-45355First seen May 15, 2026
First seen Mar 18, 2026
First seen Mar 18, 2026
CVE-2026-65165 affects Slurm Workload Manager and concerns issues involving job steps and node-count discrepancies. The affected function, underlying defect, and precise exploitation mechanism are not established.
CVE-2026-65165First seen Sep 4, 2026
First seen Oct 7, 2026
CVE-2026-59179 is a CWE-22 path-traversal vulnerability affecting @openhop/server 0.3.5 and OpenHop CLI 0.3.6. The server uses an unauthenticated flow identifier supplied through HTTP routing to construct YAML flow-storage filenames with Node.js path joining, without restricting the identifier to valid flow-name characters. URL-encoded traversal sequences are decoded by the routing layer before reaching application code; subsequent path normalization can escape the configured flow-storage directory. The affected flow retrieval operation reads the resolved YAML file, while the flow deletion operation removes it.
CVE-2026-59179First seen Sep 10, 2026
CVE-2026-50204 affects Apache Airflow single-entity endpoints and was fixed in version 3.3.0. It is distinct from CVE-2026-68969, which involves sensitive-information exposure through bulk endpoints. Detailed root-cause and exploitation information for CVE-2026-50204 is currently not available.
CVE-2026-50204First seen Aug 13, 2026
First seen Oct 2, 2026
CVE-2026-61404 affects QEMU and is addressed by adding a post_load check to its UEFI device. The precise validation failure, vulnerable code path, exploitation mechanism, and security consequences are currently not available.
CVE-2026-61404First seen Aug 30, 2026
CVE-2026-15705 is a vulnerability affecting QEMU packages associated with a denial-of-service condition exploitable through local access with high privileges. It is addressed by QEMU security updates, including Oracle Linux 9 advisory ELSA-2026-500245. The underlying defect, vulnerable function, triggering input, and complete affected-version range are currently unavailable.
CVE-2026-15705First seen Sep 8, 2026
CVE-2026-36849 is a denial-of-service vulnerability affecting libtiff 4.7.1 and earlier versions. An attacker can trigger the issue by causing the library to process a crafted TIFF file containing an excessively large SamplesPerPixel tag value. The specific vulnerable function and underlying failure mechanism are not identified.
CVE-2026-36849First seen Jun 17, 2026
Copernik XML Factory through version 0.1.1 fails to prevent XInclude resource resolution when applications enable XInclude using the stock JDK XML provider. The defect affects factories returned by XmlFactories.newDocumentBuilderFactory() and XmlFactories.newSAXParserFactory(), and XMLReader instances hardened through XmlFactories.harden(). Parsing attacker-controlled XML under these conditions can disclose local files and trigger server-side request forgery, violating the library's documented security guarantee. The Apache Xerces and Android providers are unaffected.
CVE-2026-61586First seen Oct 2, 2026
CVE-2026-104201 is an input-validation vulnerability in radsecproxy, a RADIUS protocol proxy. Incomplete validation of MS-PPPE packets can cause denial of service or potentially arbitrary code execution. Debian released a security update for its stable distribution, trixie. The specific vulnerable function and affected upstream version range are not identified.
CVE-2026-104201First seen Oct 2, 2026
CVE-2026-48004First seen Jun 1, 2026
CVE-2026-63321 affects QEMU packages. Details of the underlying vulnerability mechanism, vulnerable component or function, and complete affected-version range are currently unavailable.
CVE-2026-63321First seen Aug 30, 2026
CVE-2026-49265 is a timing side-channel vulnerability in OAuthLib's PKCE authorization-code verifier comparison. The plain PKCE comparison uses Python string equality instead of a constant-time comparison, potentially exposing a timing oracle. An attacker who intercepts an authorization code and can perform repeated, precisely timed token requests may infer the code verifier character by character and redeem the code. Exploitation could lead to access-token theft and account takeover, but is constrained by authorization-code single-use semantics and network jitter.
CVE-2026-49265First seen Sep 29, 2026
CVE-2026-65929 affects QEMU packages and is addressed by a QEMU security update to version 1:10.0.13+ds-0+deb13u1 and by Oracle Linux 9 advisory ELSA-2026-500245. Details of the vulnerability mechanism, affected functions, and exploitation behavior are currently unavailable.
CVE-2026-65929First seen Aug 30, 2026
CVE-2026-103952 is an out-of-bounds write vulnerability in Tenable Nessus versions earlier than 10.12.5. An authenticated, privileged attacker could exploit it to cause denial of service. The affected function and triggering input are not specified. Nessus 10.12.5 includes a fix.
CVE-2026-103952First seen Oct 1, 2026
CVE-2026-103950 is a type confusion vulnerability affecting Tenable Nessus versions earlier than 10.12.5. An authenticated, privileged attacker could exploit it to compromise Nessus confidentiality, integrity, or availability. The affected function and triggering input are not specified.
CVE-2026-103950First seen Oct 1, 2026
CVE-2026-103946 is an SQL injection vulnerability in Tenable Nessus versions earlier than 10.12.5. An authenticated user can exploit the vulnerability to read or modify data stored by Nessus. The affected function, injection parameter, and vulnerable endpoint are not identified. Nessus 10.12.5 fixes the vulnerability.
CVE-2026-103946First seen Oct 1, 2026
CVE-2026-103947 is an integrity-verification vulnerability in Tenable Nessus versions earlier than 10.12.5. Nessus does not sufficiently verify the integrity of certain downloaded content before using it, potentially allowing an authenticated, privileged attacker to compromise the system. The affected content types and vulnerable functions are not specified.
CVE-2026-103947First seen Oct 1, 2026