Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2026-44170 Source A vulnerability in MariaDB on Windows systems allows users to execute system commands when the CONNECT engine with REST support is enabled, due to unsafe processing of HTTP attributes. affects: ≥10.6.1 <10.6.26; ≥10.11.1 <10.11.17; ≥11.4.1 <11.4.11; ≥11.8.1 <11.8.7; =12.3.1 |
MariaDB | OS & platform | Critical | 12.06.2026 |
| CVE-2026-44169 Source In certain MariaDB versions, users with execution rights for stored routines can view their source code even without the proper authorization to do so. affects: ≥11.4.1 <11.4.11; ≥11.8.1 <11.8.7; =12.3.1 |
MariaDB | OS & platform | Medium | 12.06.2026 |
| CVE-2026-44168 Source A security flaw in MariaDB database software allows malicious clients to execute arbitrary system commands on the server by sending unvalidated parameters during data synchronization processes. affects: ≥10.6.1 <10.6.26; ≥10.11.1 <10.11.17; ≥11.4.1 <11.4.11; ≥11.8.1 <11.8.7; =12.3.1 |
MariaDB | OS & platform | High | 12.06.2026 |
| GHSA-22w5-2fxg-vrwx Source OpenTofu, an infrastructure-as-code tool, can be forced into high CPU usage by malicious servers, causing denial of service. This affects HTTP response processing and TLS certificate handling through Go standard libraries. |
OpenTofu | OS & platform | Low | 12.06.2026 |
| CVE-2026-40873 Source A security vulnerability in the mailcow email software allows attackers to execute malicious code in administrator browsers by sending emails with specially crafted attachment names, potentially leading to admin account takeover. |
Docker Engine | OS & platform | High | 12.06.2026 |
| CVE-2026-40872 Source A security vulnerability in mailcow (an email software) allows attackers to inject malicious code into admin logs that gets executed when administrators view those logs. |
Docker Engine | OS & platform | Critical | 12.06.2026 |
| CVE-2026-50011 Source A vulnerability in the Netty framework allows attackers to cause denial-of-service attacks by sending malicious Redis messages with false array size declarations that trigger excessive memory allocation. |
Redis | OS & platform | High | 12.06.2026 |
| CVE-2026-48006 Source A vulnerability in the Netty framework causes memory leaks when Redis pipeline connections close prematurely. This can exhaust the entire memory pool through repeated connection interruptions, causing all network channels to fail. |
Redis | OS & platform | High | 12.06.2026 |
| CVE-2026-6478 Source PostgreSQL databases using MD5-hashed passwords are vulnerable to a timing attack where attackers can determine user credentials by measuring authentication response times during login attempts. affects: <14.23; ≥15.0 <15.18; ≥16.0 <16.14; ≥17.0 <17.10; ≥18.0 <18.4 |
PostgreSQL | OS & platform | Medium | 12.06.2026 |
| CVE-2026-6477 Source PostgreSQL client library libpq has a buffer vulnerability where a database administrator can send arbitrarily large responses and overwrite memory in client applications like pg_dump or psql. affects: <14.23; ≥15.0 <15.18; ≥16.0 <16.14; ≥17.0 <17.10; ≥18.0 <18.4 |
PostgreSQL | OS & platform | High | 12.06.2026 |
| CVE-2026-6476 Source A vulnerability in PostgreSQL allows attackers with certain permissions to execute malicious SQL code as administrator when the pg_createsubscriber tool is used. affects: ≥17.0 <17.10; ≥18.0 <18.4 |
PostgreSQL | OS & platform | High | 12.06.2026 |
| CVE-2026-6475 Source PostgreSQL database tools unsafely follow symbolic links, allowing a superuser to overwrite arbitrary local files and compromise the operating system account. affects: <14.23; ≥15.0 <15.18; ≥16.0 <16.14; ≥17.0 <17.10; ≥18.0 <18.4 |
PostgreSQL | OS & platform | High | 12.06.2026 |
| CVE-2026-6474 Source A vulnerability in PostgreSQL's timeofday() function allows attackers to read portions of server memory by using crafted timezone specifications, potentially exposing sensitive data stored in memory. affects: <14.23; ≥15.0 <15.18; ≥16.0 <16.14; ≥17.0 <17.10; ≥18.0 <18.4 |
PostgreSQL | OS & platform | Medium | 12.06.2026 |
| CVE-2026-44890 Source A vulnerability in the Netty framework's Redis protocol component allows attackers to crash the server by sending specially crafted messages without proper line endings, exhausting memory resources. |
Redis | OS & platform | High | 12.06.2026 |
| CVE-2026-44250 Source A vulnerability in Netty's Redis codec allows attackers to cause denial-of-service attacks by sending specially crafted Redis messages with deeply nested arrays, leading to memory exhaustion. |
Redis | OS & platform | High | 12.06.2026 |
| CVE-2026-49261 Source MariaDB database server executes malicious commands embedded in node names when wsrep_notify_cmd feature is enabled, allowing attackers to gain complete system control. affects: ≥10.6.1 <10.6.27; ≥10.11.1 <10.11.18; ≥11.4.1 <11.4.12; ≥11.8.1 <11.8.8; =12.3.1 |
MariaDB | OS & platform | Critical | 11.06.2026 |
| CVE-2026-6473 Source A flaw in PostgreSQL allows regular database users to cause memory errors through large inputs, potentially leading to arbitrary code execution on the server. affects: <14.23; ≥15.0 <15.18; ≥16.0 <16.14; ≥17.0 <17.10; ≥18.0 <18.4 |
PostgreSQL | OS & platform | High | 11.06.2026 |
| CVE-2026-6472 Source A vulnerability in PostgreSQL allows attackers to create malicious data types that can be unintentionally used by other users, leading to execution of harmful SQL functions. affects: <14.23; ≥15.0 <15.18; ≥16.0 <16.14; ≥17.0 <17.10; ≥18.0 <18.4 |
PostgreSQL | OS & platform | Medium | 11.06.2026 |
| CVE-2026-54761 Source A flaw in Traefik's Kubernetes Gateway provider allows unauthorized exposure of internal Traefik services by bypassing namespace validation for crossProviderNamespaces allowlists. |
Traefik | OS & platform | Medium | 11.06.2026 |
| CVE-2026-54302 Source A vulnerability in n8n workflow software allows authenticated users with editing permissions to inject malicious JavaScript code into Chat Trigger pages, which then executes in other users' sessions. |
n8n | Self-hosted apps | High | 10.06.2026 |
| CVE-2026-54303 Source A security vulnerability in the n8n workflow automation software allows cross-site scripting attacks when logged-in users visit specially crafted URLs, enabling attackers to execute malicious code in the user's browser. |
n8n | Self-hosted apps | Medium | 10.06.2026 |
| CVE-2026-54312 Source A vulnerability in n8n allows authenticated users to cause global prototype pollution through the Microsoft SQL node, rendering the entire n8n server non-functional until restart. |
n8n | Self-hosted apps | High | 10.06.2026 |
| CVE-2026-54311 Source A vulnerability in the n8n workflow software allows authenticated users to access other users' workflow data through the Merge node's SQL mode, because the sandbox context is shared and reused across different workflow executions. |
n8n | Self-hosted apps | Medium | 10.06.2026 |
| CVE-2026-54306 Source A vulnerability in the n8n workflow software allows attackers to inject malicious data through public webhooks into workflows, potentially causing downstream actions to execute with incorrect data or credentials. |
n8n | Self-hosted apps | Medium | 10.06.2026 |
| CVE-2026-54301 Source A security vulnerability in the n8n workflow software allows authenticated users to inject malicious JavaScript code into other users' browsers through webhook nodes, potentially stealing their session data. |
n8n | Self-hosted apps | High | 10.06.2026 |
| CVE-2026-54308 Source A vulnerability in n8n workflow software allows attackers to send fake data to certain webhook nodes and execute workflows with manipulated content without requiring authentication. |
n8n | Self-hosted apps | Medium | 10.06.2026 |
| GHSA-hv7x-3x78-gx53 Source A vulnerability in the n8n workflow automation software allows users with only read permissions to execute workflows despite lacking execution permissions. This can result in unintended API calls and data modifications in connected systems. |
n8n | Self-hosted apps | Medium | 10.06.2026 |
| CVE-2026-54313 Source A security vulnerability in the n8n workflow software allows authenticated users with editing permissions to inject malicious filter queries through the MongoDB node, potentially overwriting unintended database documents with attacker-controlled content. |
n8n | Self-hosted apps | Medium | 10.06.2026 |
| CVE-2026-54310 Source A vulnerability in the n8n workflow software allows authenticated users to inject malicious SQL commands through TimescaleDB and Postgres nodes and execute them on the connected database. |
n8n | Self-hosted apps | Medium | 10.06.2026 |
| CVE-2026-54304 Source A vulnerability in the n8n workflow software allows authenticated users to send SecurityScorecard API tokens to attacker-controlled servers, potentially exposing sensitive credentials to unauthorized parties. |
n8n | Self-hosted apps | High | 10.06.2026 |
| CVE-2026-54309 Source A security flaw in n8n's browser control component allows unauthenticated attackers to control browser functions when HTTP transport is used. This enables strangers to access cookies, website data, and execute JavaScript in the user's browser. |
n8n | Self-hosted apps | High | 10.06.2026 |
| CVE-2026-54305 Source A security flaw in n8n Enterprise software allows authenticated users to access and hijack other users' credentials, potentially leading to data theft or workflow disruption. |
n8n | Self-hosted apps | High | 10.06.2026 |
| CVE-2026-54307 Source In the n8n workflow automation software, users with editor access to shared workflows can access credentials they don't own through specific API endpoints due to incomplete ownership verification checks. |
n8n | Self-hosted apps | High | 10.06.2026 |
| GHSA-664h-gpgq-h6xx Source A vulnerability in n8n allows users with limited read permissions to start, cancel, and delete workflow test runs even though they should only have read access. |
n8n | Self-hosted apps | Medium | 10.06.2026 |
| CVE-2026-54314 Source A vulnerability in n8n's Compression node allows attackers to cause memory exhaustion and crash all workflows by sending small compressed archives to public webhooks, as the decompression operation lacks size limits. |
n8n | Self-hosted apps | Medium | 10.06.2026 |
| CVE-2026-49220 Source A vulnerability in Jellyfin allows regular users to inject malicious JavaScript code into administrators' browsers when they view certain user settings in the dashboard. |
Jellyfin | Self-hosted apps | Medium | 10.06.2026 |
| CVE-2026-49246 Source A security vulnerability in Jellyfin allows specially crafted MKV video files to write files to arbitrary locations on the server through manipulated filename tags when the video is played back. |
Jellyfin | Self-hosted apps | Low | 10.06.2026 |
| CVE-2026-49247 Source A vulnerability in Jellyfin allows authenticated users to create arbitrary files on the server by manipulating client information, potentially compromising the system. |
Jellyfin | Self-hosted apps | Medium | 10.06.2026 |
| CVE-2026-48793 Source A security vulnerability in Jellyfin allows attackers to inject malicious commands through specially named subtitle files, enabling arbitrary file writing on the server or information theft. |
Jellyfin | Self-hosted apps | High | 10.06.2026 |
| CVE-2026-41719 Source A security vulnerability in Spring Data KeyValue allows attackers to execute malicious code when unsanitized user input is passed as sorting parameters to repository queries. affects: ≥2.7.0 <2.7.20; ≥3.0.0 <3.0.16; ≥3.1.0 <3.1.15; ≥3.2.0 <3.2.16; ≥3.3.0 <3.3.17; ≥3.4.0 <3.4.15; ≥3.5.0 <3.5.11.1; ≥4.0.0 <4.0.5.1 |
Redis | OS & platform | Medium | 10.06.2026 |
| CVE-2026-46316 Source A flaw in the Linux kernel allows memory references to be freed multiple times when multiple processes concurrently access the same cache entry, potentially causing memory corruption. |
Redis | OS & platform | Critical | 09.06.2026 |
| CVE-2026-52846 Source A vulnerability in Caddy's stripHTML function allows certain malformed HTML tags to bypass removal, potentially letting malicious code through that could lead to cross-site scripting attacks. |
Caddy | OS & platform | Medium | 09.06.2026 |
| CVE-2026-52845 Source A vulnerability in the Caddy web server allows attackers to bypass authentication header filtering by using underscores instead of hyphens, as these become identical PHP variables during FastCGI processing. |
Caddy | OS & platform | High | 09.06.2026 |
| CVE-2026-52844 Source A security flaw in Caddy on Windows systems allows attackers to bypass path-based access controls by using backslashes in URLs to access protected files that should be blocked. |
Caddy | OS & platform | High | 09.06.2026 |
| GHSA-wpr2-j6gr-pjw9 Source OpenTofu may accidentally expose sensitive variables in module sources and backend configurations when static evaluation is enabled, even though this should be blocked. |
OpenTofu | OS & platform | Low | 07.06.2026 |
| GHSA-w2jf-268q-mrvh Source OpenTofu, an infrastructure-as-code tool, is vulnerable to denial-of-service attacks during module installation when maliciously crafted TLS certificates or archives from untrusted sources are used, potentially causing high CPU usage or memory consumption. |
OpenTofu | OS & platform | Low | 07.06.2026 |
| GHSA-mjcp-gpgx-ggcg Source OpenTofu incorrectly validates TLS certificates when excluded subdomains and wildcard certificates are combined, allowing attackers with valid but contradictory certificates to potentially establish connections to protected servers. |
OpenTofu | OS & platform | Medium | 07.06.2026 |
| GHSA-r92c-9c7f-3pj8 Source OpenTofu, an infrastructure-as-code tool, is vulnerable to denial-of-service attacks through maliciously crafted ZIP archives when installing modules or providers, causing high CPU usage. |
OpenTofu | OS & platform | Low | 07.06.2026 |
| GHSA-hw5x-4r37-72w7 Source OpenTofu can be crashed when installing modules from untrusted sources through malicious TLS certificates or tar archives, causing unbounded memory usage or high CPU load. |
OpenTofu | OS & platform | Low | 07.06.2026 |
| GHSA-wcmj-x466-56mm Source OpenTofu follows symbolic links in the .terraform/providers directory during provider installation and can write files to arbitrary directories when an attacker controls the working directory. |
OpenTofu | OS & platform | Medium | 07.06.2026 |