submitted by /u/Sandwich_1337
[link] [comments]
Normal view
-
/r/netsec - Information Security News & Discussion
- Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)
-
/r/netsec - Information Security News & Discussion
- Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
-
/r/netsec - Information Security News & Discussion
- Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
15 June 2026 at 20:38
While fuzzing the Kubernetes AWS KMS provider, researchers at Syntetisk found a denial-of-service issue in aws-encryption-provider where an empty ciphertext field could trigger an unrecovered Go panic and crash the plugin process.
The writeup includes root-cause analysis, crash path details, reproducer examples, impact discussion, and disclosure timeline
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
4 June 2026 at 14:54
-
/r/netsec - Information Security News & Discussion
- Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB)
Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB)
1 June 2026 at 20:44
Came across an article, product like phpBB still has some potential flaws.
[link] [comments]