,

Vulnerability Watch No33

🔐 Bouncy Castle FIPS Key Zeroisation Can Fall Behind on Newer JVMs
Teams using affected BC-FJA releases should upgrade to the corrected versions, particularly where the finalizer-backed zeroisation behavior is problematic under their JVM and workload. The entry specifically says this behavior was not a problem on Java 8 or Java 11, and that standard Bouncy Castle for Java and Bouncy Castle for Java LTS are not affected.
CVE-2026-13505 affects Bouncy Castle for Java FIPS before bc-fips 1.0.2.7 in the 1.0.X series, 2.0.2 in the 2.0.X series, and 2.1.3 in the 2.1.X series, where sensitive key material relied on Java finalization for zeroisation. Delayed finalization on affected later JVM environments can leave key material resident in memory longer than intended and contribute to OutOfMemoryError conditions under load. The vulnerability is rated HIGH with CVSS 8.7.
🔗 Read more 🔗
Source: NVD

🎲 Bouncy Castle FIPS Entropy Failure Can Hang Applications
Operators using affected BC-FJA 2.1.x deployments with the native entropy source should move to 2.1.3 promptly, particularly on systems where entropy instructions may fail persistently. The affected thread can remain trapped inside the JNI retry loop and cannot be interrupted or timed out.
CVE-2026-8798 affects Bouncy Castle for Java FIPS before bc-fips 2.1.3 on Intel platforms. Unbounded retries of RDSEED and RDRAND could leave a calling thread stuck indefinitely when the hardware entropy source persistently fails, causing denial of service. The vulnerability is rated HIGH with CVSS 8.7.
🔗 Read more 🔗
Source: NVD

🐢 Klever-Go REST APIs Exposed to Slow-Header Denial of Service
Internet-reachable Klever-Go REST endpoints should be upgraded to 1.7.18 as a priority. Nodes exposed through an all-interface bind or Docker port publishing are particularly susceptible to this low-cost remote denial-of-service attack.
CVE-2026-52880 affects Klever-Go versions 1.7.14 through 1.7.17. Its REST servers lack HTTP header and read timeouts, allowing an unauthenticated remote client to hold many incomplete connections open until file descriptors are exhausted and the API becomes unavailable. The vulnerability is rated HIGH with CVSS 7.5 and is fixed in version 1.7.18.
🔗 Read more 🔗
Source: NVD

🧵 Klever-Go Peer Can Trigger Unbounded Goroutine Creation
Klever node operators should upgrade to 1.7.18 promptly, especially validators and publicly reachable peers. A single connected peer can trigger the resource-exhaustion condition before the processor-level antiflood logic makes its admission decision.
CVE-2026-52879 affects Klever-Go versions 1.7.14 through 1.7.17. A connected peer can send direct messages that cause goroutines to be spawned before antiflood checks run, enabling unbounded concurrency, scheduler pressure, and memory pressure that can degrade node availability. The vulnerability is rated HIGH with CVSS 7.5 and is fixed in version 1.7.18.
🔗 Read more 🔗
Source: NVD

💥 Tiny Malformed Transaction Can Crash Klever-Go Nodes
Validator and full-node operators should treat the upgrade to 1.7.18 as urgent. The attack requires no validator key, stake, funds, or on-chain account, and targeting enough of the validator set could halt block production.
CVE-2026-52878 affects Klever-Go versions 1.7.14 through 1.7.17. A specially crafted 3-byte protobuf transaction with omitted RawData can trigger a nil-pointer panic that propagates through the P2P validation path and crashes the entire node process. The vulnerability is rated HIGH with CVSS 7.5, can potentially halt block production if enough validators are targeted, and is fixed in version 1.7.18.
🔗 Read more 🔗
Source: NVD

📝 Malicious Kakoune Backup Files Can Execute Shell Commands
Kakoune users should upgrade to 2026.05.21 promptly because malicious backup files can trigger command execution when a file is opened. Until upgrading, adding autorestore-disable to the user kakrc disables the vulnerable autorestore feature.
CVE-2026-48120 affects Kakoune before version 2026.05.21. The enabled-by-default autorestore.kak script can be exploited through malicious backup files, resulting in arbitrary Kakoune and shell command execution simply by opening a file. The vulnerability is rated HIGH with CVSS 8.6 and is fixed in Kakoune 2026.05.21.
🔗 Read more 🔗
Source: NVD

🧪 lakeFS Markdown Rendering Enables Stored Cross-Site Scripting
lakeFS administrators should upgrade OSS deployments to 1.81.1 or Enterprise deployments to 1.84.0 promptly. Enterprise users on older versions can temporarily disable Markdown rendering, while the entry states that no workaround exists for the OSS release.
CVE-2026-48026 affects lakeFS before version 1.81.1 and lakeFS Enterprise before version 1.84.0. A user with repository write access can store arbitrary HTML or JavaScript in Markdown files, including README.md, which executes when another authenticated user views the affected content in the Web UI. The vulnerability is rated HIGH with CVSS 8.7.
🔗 Read more 🔗
Source: NVD

🚨 WGDashboard Command Injection Enables Root-Level RCE
Organizations running WGDashboard 4.2.3 or earlier should treat this as an urgent remediation priority. An authenticated attacker who exploits the command injection can execute arbitrary commands with root privileges.
CVE-2026-15733 affects WGDashboard version 4.2.3 and earlier. Multiple OS command injection vulnerabilities allow authenticated attackers to execute arbitrary commands as root, resulting in remote code execution. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD

🔥 Progress LoadMaster RCE Is Actively Exploited in the Wild
Operators of affected Progress ADC products should act immediately, apply vendor mitigations, and follow applicable CISA BOD 26-04 guidance. Because exploitation is already occurring in the wild, internet-exposed appliances should receive the highest priority, and the entry advises discontinuing use if mitigations are unavailable.
CVE-2026-8037 affects Progress ADC products, including LoadMaster, through OS command injection in multiple API command endpoints. An unauthenticated attacker can supply unsanitized input to execute arbitrary commands on the appliance. The entry provides no CVSS score or explicit severity rating, but CISA lists the vulnerability in its Known Exploited Vulnerabilities catalog and states that it is actively exploited in the wild.
🔗 Read more 🔗
Source: CISA KEV

🌐 Chrome Worker Flaw Can Bypass Site Isolation
Chrome users and managed enterprise fleets should update to 151.0.7922.109 or later promptly. The issue requires prior renderer compromise, but successful exploitation can bypass the browser’s site-isolation security boundary.
CVE-2026-19153 affects Google Chrome before version 151.0.7922.109. Insufficient validation of untrusted input in Workers can allow an attacker who has already compromised the renderer process to bypass site isolation using a crafted HTML page. The vulnerability is rated HIGH with CVSS 8.1.
🔗 Read more 🔗
Source: NVD

🎮 GPU Firmware Trust Flaw Enables Data Corruption from the REE Kernel
Organizations should prioritize remediation for affected platforms when vendor guidance becomes available, particularly where compromise of the REE kernel is a realistic threat. This is a post-compromise GPU firmware and data-integrity risk because exploitation depends on attacker control of the non-secure operating-system kernel.
CVE-2026-45198 affects GPU firmware on platforms with Trusted Execution Environment support. An attacker controlling the non-secure Rich Execution Environment kernel can modify a pointer in non-secure memory, corrupting data used by GPU firmware when internal data is saved to or retrieved from main memory. The vulnerability is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD

🧠 Improper GPU Calls Can Expose Kernel Memory and Trigger UAF
Systems that allow non-privileged software to access the affected GPU functionality should prioritize vendor remediation when it becomes available. The combination of kernel-memory out-of-bounds reads and potential use-after-free makes the issue important for systems with untrusted or isolated user workloads.
CVE-2026-49746 involves incorrect validation of an array index in GPU system-call handling. Software running as a non-privileged user can make improper GPU system calls that cause an out-of-bounds read of kernel memory and, in some cases, a GPU use-after-free involving arbitrary pages. The vulnerability is rated HIGH with CVSS 7.1.
🔗 Read more 🔗
Source: NVD