CSSA Exclusive Early Warning10.0 Critical
OpenSSL QUIC listener object lifecycle management defect leading to denial of service
An attacker can exploit a logic defect in SSL_listen_ex when detaching the inbound channel, causing the new connection object to be incorrectly bound to the listener hierarchy while retaining a freed pointer, producing a use-after-free condition. Because the returned connection cannot complete the handshake yet retains invalid internal state, subsequent BIO operations or destructor cleanup may access a dangling pointer or an uninitialized thread assist worker, causing out-of-bounds memory access or abnormal process termination and achieving denial of service against the affected service.
Component
OpenSSL is a widely deployed cryptographic communication library whose core purpose is to provide secure network transport, and since the introduction…
Type
Use After Free (CWE-416)
Repo
Remediation- It is recommended to enforce strict lifecycle validation when handling QUIC connection objects, ensuring correct ownership transfer and state initialization complete before detachment. The development team should fix test cases to accurately capture handshake failure scenarios and add defensive checks for invalid object state in production to prevent illegal memory access.
CSSA Exclusive Early Warning10.0 Critical
sub2api image download endpoint lacking URL validation leading to SSRF, internal network probing and cloud credential disclosure
An attacker can use the /v1/images/generations endpoint to inject a malicious image_url parameter into the request body. Because the backend downloadOpenAIImageBytes function performs no validity check on the destination address, the server issues an HTTP GET request directly to that URL. This defect allows an attacker to reach internal network resources or cloud provider metadata services with the server's identity, leading to theft of sensitive credentials, internal port scanning and potential service disruption.
Component
sub2api is a Go-based proxy gateway component designed for OpenAI API protocol compatibility to provide image generation services. Its core architectu…
Type
SSRF (CWE-918)
Repo
Remediation- It is recommended to enforce a strict URL allowlist limiting access to trusted CDN domains, add IP address range filtering that rejects requests resolving to loopback, private network segments and link-local addresses, and introduce DNS rebinding protection to ensure request safety.
CVE-2026-76193CVSS 10.0 Critical2026-08-26
Adobe Campaign Classic Server-Side Request Forgery Leading to Arbitrary Code Execution
Adobe Campaign Classic (ACC) contains a server-side request forgery (SSRF) vulnerability (CWE-918) that may result in arbitrary code execution in the context of the current user. An attacker can exploit it to execute arbitrary code, and exploitation requires no user interaction. The scope is changed, the attack vector is network-based with low attack complexity, no privileges and no user interaction are required, and the impact on confidentiality, integrity and availability is high.
Component
Adobe Campaign Classic (ACC) is an enterprise customer experience management platform from Adobe used to manage large-scale marketing campaigns, customer engagement and data analysis.
Risks
- Complete system control: An attacker can execute arbitrary code on the victim system, and depending on current user privileges, install programs, view/modify/delete data or create new accounts with full privileges
- No user interaction required: Exploitation requires no user interaction; an attacker can trigger the vulnerability remotely over the network without luring users into clicking or performing any action
- High-impact damage: With a CVSS score of 10.0, the vulnerability seriously threatens system confidentiality, integrity and availability, potentially causing data disclosure, system tampering or service disruption
Source
Remediation- Deploy network-layer protection to restrict what external resources the server may request
- Monitor anomalous network request behavior, particularly unexpected outbound connections initiated from within application servers
CVE-2026-49845CVSS 9.8 Critical2026-08-25
Apache Hive Metastore SQL Injection Leading to Unintended Partition Metadata Tampering
In Apache Hive prior to version 4.2.1, the Hive Metastore module does not use bound parameters when parsing partition names in direct SQL, resulting in SQL injection (CWE-94). When direct SQL is enabled (the default), an authenticated user can craft a malicious partition name containing a single quote in a Metastore RPC request to alter the generated WHERE clause, reading, modifying or affecting unintended partition metadata including statistics updates, truncation targets and file metadata cache operations. The vulnerability affects all Apache Hive users who have not updated to 4.2.1 and is present at risk under default configuration. An attacker needs Hive Metastore API access but can trigger the vulnerability remotely with no additional user interaction, compromising data integrity and confidentiality.
Component
Apache Hive is a Hadoop-based data warehouse platform providing data summarization, query and analysis; Hive Metastore is its core component responsible for storing and managing metadata.
Risks
- Metadata integrity damage: An attacker can tamper with partition statistics, truncate the wrong partition or overwrite the file metadata cache, causing incorrect analysis results or data loss
- Unintended data reading: Through crafted SQL injection, an attacker can read metadata of other partitions they should not be able to access, causing information disclosure
- Service availability impact: Malicious metadata operations may cause Hive query failures or instability in cluster metadata services
Source
Remediation- Immediately upgrade Apache Hive to version 4.2.1 or later to fix this vulnerability
- If an immediate upgrade is not possible, consider disabling direct SQL in configuration (setting metastore.try.direct.sql to false), noting the potential performance impact
- Monitor Hive Metastore logs to detect anomalous partition name requests or SQL execution errors
Package Poisoningnpm2026-08-26
video-crate-check@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
b6e4b0ebdbced85be25afce02f96127b
Package Poisoningnpm2026-08-26
dim-svelte-ui@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
79a6e5f110d2cb98c9f4eb3ea907ead5
Package Poisoningnpm2026-08-26
foldmap@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
8d169bb521c0d8bfac7a3392e91586b7
Package Poisoningnpm2026-08-26
snapbuf@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
baf1194cbb49351eecfcd42cefa140c1
Package Poisoningnpm2026-08-26
svelte-cls-ui@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
6a2584b73187f37ff11840990f7fd015
Package Poisoningnpm2026-08-26
tailwind-scrollbar-hider@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
355da2493d77fd98b8c1ebfb27ccd215
Package Poisoningnpm2026-08-26
wm-eslint-fe@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
40c0f64bf298e095e08c26d8d07284c2
Package Poisoningnpm2026-08-26
array-shuffler-utils-99@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
d1ad4df3c8c6f8ced9916ba2adb646cb
Package Poisoningnpm2026-08-26
fivem-tool-helper@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
166b6e97d6b9fa31581166abf409010e
Package Poisoningnpm2026-08-26
fivem-tool-helper-v2@>= 0 flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
1ea028ac42fbe1ceb74eb935d943ffb3