CSSA Exclusive Early Warning9.8 Critical
Node.js HTTP/2 module use-after-free triggered by malicious data leading to service disruption
An attacker can send carefully crafted HTTP/2 data streams to the target node over the network interface, exploiting lifecycle management defects in the protocol stack when handling stream reset or close states. This causes the underlying nghttp2 session memory manager to free allocated stream control structures prematurely, after which the dangling pointer region is accessed again during subsequent data frame reception, triggering a heap use-after-free condition. The exploitation path is low-complexity and requires no interaction; without prior privileges an attacker can remotely trigger illegal reads and writes in core threads. Affected instances face execution flow hijacking and sustained denial of service, with impact spanning every exposed node that has HTTP/2 enabled.
Component
Node.js is a cross-platform JavaScript runtime built on the Chrome V8 engine. Its core architecture uses an event-driven, non-blocking I/O model to su…
Type
Use After Free (CWE-416)
Repo
Remediation- It is recommended to introduce strict lifecycle management, nulling pointers immediately after memory is freed and intercepting secondary references, restructuring the resource reclamation flow around a reference counting strategy, and validating boundary conditions with static scanning and address sanitizers to eliminate dangling pointer hazards.
CVE-2026-58455CVSS 9.8 Critical2026-07-03
Dockwatch Unauthenticated OS Command Injection Leading to Complete Host Control
In Dockwatch 0.6.567 and earlier, the loader.php file lacks an exit() call after authentication redirection, which combined with unfiltered input passed to shell_exec() in ajax/compose.php results in an operating system command injection (CWE-78) security flaw. An attacker can set the required session flag through the incomplete authentication check and then inject arbitrary commands via the composePath POST parameter in the composePull operation, executing arbitrary shell commands. The vulnerability allows a remote attacker to achieve complete host control without authentication, and the standard Docker socket mount deployment pattern further amplifies this risk. It affects all Dockwatch users who have not updated to a patched version, particularly those using the standard Docker socket mount deployment. An attacker only needs to send a crafted HTTP request to exploit it, requiring no user interaction and allowing remote control.
Component
Dockwatch is an open-source tool for monitoring and managing Docker containers, supporting container operations and management through a web interface.
Risks
- From standard user to administrator: If the victim runs the Dockwatch service with administrative privileges, the attacker gains the same privileges
- Complete system control: An attacker can execute arbitrary code on the victim system, and depending on user privileges, install programs, view/modify/delete data or create new accounts with full privileges
- No user interaction required: The vulnerability triggers directly through a remote network request; the attacker achieves host takeover without luring the user into any interaction
Source
Remediation- Restrict network access to the Dockwatch web interface and allow connections only from trusted IP addresses
- Avoid running the Dockwatch container as root and restrict Docker socket mount permissions
CVE-2026-57100CVSS 9.9 Critical2026-07-03
Microsoft Entra Provisioning Service Server-Side Request Forgery Leading to Privilege Escalation
In Microsoft Entra Provisioning Service (SyncFabric), the lack of effective validation of server-side requests results in a server-side request forgery (SSRF, CWE-918) security flaw. An authenticated attacker can use this vulnerability to escalate privileges over the network. It allows an attacker to craft a malicious request causing the server to reach internal networks or other restricted resources, obtaining sensitive information or performing unauthorized operations. The vulnerability affects all unpatched Microsoft Entra Provisioning Service deployments. An attacker needs some initial (low) privileges but can trigger exploitation remotely over the network without user interaction.
Component
Microsoft Entra Provisioning Service (SyncFabric) is part of Microsoft Entra ID (formerly Azure Active Directory), responsible for identity synchronization and provisioning services, ensuring data consistency and security between on-premises directories and cloud identities.
Risks
- Privilege escalation: An authenticated attacker can escalate privileges over the network, potentially moving from a low-privilege account to higher privileges
- Internal network probing and attack: Through the SSRF flaw an attacker can reach internal network resources to perform port scanning, service discovery or attacks against internal applications
- Data disclosure: An attacker may read internal sensitive data or configuration files, resulting in disclosure of confidential information
Source
Remediation- Immediately apply the security patches or updates released by Microsoft
- Configure network access control lists (ACLs) to restrict server-side access to specific external and internal ports
- Deploy a web application firewall (WAF) to detect and block anomalous SSRF request patterns
Package Poisoningnpm2026-07-03
robomerge@99999.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
a69b9ecfab6d38a43b3edbbe31ae19fa
Package Poisoningnpm2026-07-03
ue-automation-scripts@99999.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
a5e3ec4aa25880e90bd7924414988f9f
Package Poisoningnpm2026-07-03
ue-jenkins-buildkite@99999.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
8754f459aedb021d60b637b7e9ee9a03
Package Poisoningnpm2026-07-03
unreal-horde-dashboard@99999.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
c086aa6b8eee7884a76df6ae9fc7372e
Package Poisoningnpm2026-07-03
epic-internal-tools@99999.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
b50521f57accfcbee27ac9be6c318316
Package Poisoningpypi2026-07-04
procwire@5.2.3 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
d57b909fa7511d0d4fa04662331f4616
Package Poisoningpypi2026-07-04
bytekit@3.4.2 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
53fd6b2e815f9f889972451af38b529f
Package Poisoningpypi2026-07-04
confighub@7.0.2 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
409848feddfd073f6cecd7760b3a5f73
Package Poisoningpypi2026-07-04
schemavault@4.1.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
ef895991c052300866f5e5bfd38dc840
Package Poisoningpypi2026-07-05
httpprobe@1.0.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
a772018efcd67236f51ad25a6849ba46
Package Poisoningpypi2026-07-05
urlllib321@2.7.0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
42b9219ae0b45ddcb823f53ffebce144