CVE-2026-73080CVSS 9.3 Critical2026-08-12
SeaweedFS Unauthenticated SSRF Leading to Cloud Metadata Disclosure
In SeaweedFS prior to version 4.24, the VolumeServer.FetchAndWriteNeedle function in weed/server/volume_grpc_remote.go contains a serious security flaw. The function fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle, performing no authentication or destination validation. This allows anyone able to reach the volume server gRPC port to issue requests to arbitrary hosts — including loopback, link-local, RFC 1918 private addresses and cloud metadata endpoints such as 169.254.169.254 — and read the responses. In cloud deployments this can lead to disclosure of instance metadata and IAM credentials and access to otherwise unexposed internal services. The volume server gRPC plane has no authentication enabled by default, and the JWT signing key mentioned in the configuration documentation does not protect this RPC. The issue was fixed in version 4.24.
Component
SeaweedFS is a distributed storage system designed to store and serve billions of files with ease.
Risks
- Cloud credential disclosure: An attacker can read cloud instance metadata and obtain IAM credentials, taking over cloud account privileges
- Internal network penetration: An attacker can reach unexposed internal services for lateral movement or further attack
- Unauthenticated exploitation: Because the gRPC plane has no authentication by default, an attacker needs no credentials to launch the attack
- Complete system control: After obtaining cloud credentials, an attacker may gain full control of the cloud infrastructure
Source
Remediation- Immediately upgrade SeaweedFS to version 4.24 or later
- Restrict network access to the volume server gRPC port, allowing connections only from trusted IP addresses
- Disable or restrict access to metadata endpoints such as 169.254.169.254 in cloud environments
CVE-2026-71384CVSS 9.6 Critical2026-08-12
Adobe Component Improper Authorization Bypassing Security Features Leading to Unauthorized Access and Denial of Service
An improper authorization vulnerability may result in a security feature bypass. An attacker can exploit it to bypass security measures and obtain unauthorized read and write access, potentially causing application denial of service. By default the vulnerable component is restricted to the administrative network zone. Exploitation requires no user interaction. Scope is changed. The vulnerability affects all unpatched Adobe components; an attacker can launch the attack from an adjacent network and achieve a security feature bypass without user interaction, causing high confidentiality, integrity and availability impact.
Component
Adobe is a global provider of digital media and digital experience solutions whose software is widely used across creative work, document management and digital marketing.
Risks
- Unauthorized read and write access: An attacker can bypass security mechanisms to obtain unauthorized read and write access to system data
- Application denial of service: Exploitation may crash the target application or leave it unresponsive, disrupting service
- Adjacent network attack: The attacker must be within an adjacent network zone but needs no user interaction, lowering the barrier to exploitation
Source
Remediation- Restrict access to the administrative network zone and enforce strict network isolation
- Monitor logs for anomalous authorization requests and security feature bypass behavior
Package Poisoningnpm2026-08-12
base65-11x@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
64d4b6f0c83a72a7639d6eb1f8c90081
Package Poisoningnpm2026-08-12
base65-13x@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
5c0f6f0c3668dadc1d0025e22d451501
Package Poisoningnpm2026-08-12
base65-15x@5.0.2 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
92fa050c6094d46b81d456ffbba00678
Package Poisoningnpm2026-08-12
base65-33x@5.0.2 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
e5fc278e5bf32bed5e8e257584a6e22a
Package Poisoningnpm2026-08-12
base65-77x@5.0.2 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
6411c497a62cad0fcbeb70c7fc2a0594
Package Poisoningnpm2026-08-12
bs58-11@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
145f295335be81d7c847e3f3a95c132e
Package Poisoningnpm2026-08-12
bs58-12@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
c304aedc8b2128db4ad65835425f4c11
Package Poisoningnpm2026-08-12
internallib_v164@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
60883016233e92a9555b220803520378
Package Poisoningnpm2026-08-12
sui-bcs-codec@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
ecdfe8481df8b52ac16b25209f7b3652
Package Poisoningnpm2026-08-12
sui-gql-client@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
9b192eab20fab0ca821a8f0a82837394