Latest CVE

Latest Vulnerabilities

  • CVE-2026-84887 - simular-ai Agent-S Denial of Service Vulnerability

    CVE ID :CVE-2026-84887
    Published : Sept. 2, 2026, 10:20 p.m. | 1 hour, 12 minutes ago
    Description :A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component Model-generated GUI Action Execution Workflow. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
    Severity: 0.0 | NA
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-84886 - simular-ai Agent-S OCR HTTP API Resource Consumption Vulnerability

    CVE ID :CVE-2026-84886
    Published : Sept. 2, 2026, 10:20 p.m. | 1 hour, 12 minutes ago
    Description :A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of the component OCR HTTP API. Executing a manipulation of the argument img_bytes can lead to resource consumption. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
    Severity: 0.0 | NA
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-84888 - RightNow-AI OpenFang Uncontrolled Memory Allocation

    CVE ID :CVE-2026-84888
    Published : Sept. 2, 2026, 10:20 p.m. | 1 hour, 12 minutes ago
    Description :A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec of the file crates/openfang-runtime/src/tool_runner.rs. This manipulation causes uncontrolled memory allocation. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
    Severity: 0.0 | NA
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-66049

    CVE ID :CVE-2026-66049
    Published : Sept. 2, 2026, 9:05 p.m. | 2 hours, 27 minutes ago
    Description :None
    Severity: 0.0 | NA
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-66048

    CVE ID :CVE-2026-66048
    Published : Sept. 2, 2026, 9:05 p.m. | 2 hours, 27 minutes ago
    Description :None
    Severity: 0.0 | NA
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-84851 - Amazon Ion-C Uncontrolled Recursion Denial of Service

    CVE ID :CVE-2026-84851
    Published : Sept. 2, 2026, 9:05 p.m. | 2 hours, 27 minutes ago
    Description :An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service.
    Severity: 7.5 | HIGH
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-84394 - fast-uri Host Parsing SSRF Vulnerability

    CVE ID :CVE-2026-84394
    Published : Sept. 2, 2026, 9:05 p.m. | 2 hours, 27 minutes ago
    Description :fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as an IP literal nor canonicalized as a domain name, so parse() returns it as the host with error undefined, while Node's URL and the HTTP clients built on it resolve the same string to a different host. An application that reads the parsed host to make a host decision, such as an SSRF denylist, a redirect allowlist, or proxy routing, and then passes the original URL to an HTTP client evaluates its policy against a string that is not the host the request reaches. The same host is carried through normalize, equal, and resolve. This affects fast-uri versions 2.4.5, 3.1.6, and 4.1.3, and is fixed in 2.4.6, 3.1.7, and 4.1.4, where parse() reports a malformed host for any host that contains a bracket but is not a valid IPv6 literal.
    Severity: 7.5 | HIGH
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-84885 - Simular-AI Agent-S CodeAgent Denial of Service Vulnerability

    CVE ID :CVE-2026-84885
    Published : Sept. 2, 2026, 9:05 p.m. | 2 hours, 27 minutes ago
    Description :A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
    Severity: 0.0 | NA
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-84857 - Sigoedn Aichat API Endpoint Uncontrolled Memory Allocation

    CVE ID :CVE-2026-84857
    Published : Sept. 2, 2026, 8:17 p.m. | 3 hours, 15 minutes ago
    Description :A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the component API Endpoint. This manipulation causes uncontrolled memory allocation. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
    Severity: 5.5 | MEDIUM
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-84856 - Rowboat Composio Webhook Endpoint Denial of Service Vulnerability

    CVE ID :CVE-2026-84856
    Published : Sept. 2, 2026, 8:17 p.m. | 3 hours, 15 minutes ago
    Description :A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json of the file apps/rowboat/app/api/composio/webhook/route.ts of the component Composio Webhook Endpoint. The manipulation results in denial of service. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version 0.9.2 is sufficient to resolve this issue. Upgrading the affected component is recommended. The legacy Next.js app was deleted at 0.9.2 rather than patched, leaving no security control behind.
    Severity: 5.5 | MEDIUM
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
| Date published: Wed, 02 Sep 2026 22:20:43 +0000
Back to newsfeed list