Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Compliance-trestle versions before 3.12.4 and versions 4.0.0 through 4.0.3 contain a vulnerability in the URLSecurityValidator that allows bypassing its blocklist for certain internal and cloud metadata IP addresses. This flaw enables attackers to cause the software to fetch data from restricted internal network endpoints, including loopback and cloud instance-metadata services. The issue arises because the validator does not properly canonicalize IPv4-mapped IPv6 literals and does not block the unspecified address 0.0.0.0. The vulnerability is fixed in versions 3.12.4 and 4.1.0. Join the discussion | GCVE Database | 08/25/2026, 23:12:24 UTC Added: 08/12/2026, 16:11:23 UTC |
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not properly validate, `../`, `..\`, or absolute paths. This allows arbitrary file write to attacker-controlled locations. Versions 3.12.3 and 4.0.3 patch the issue. Join the discussion | CVE Database V5 | 08/17/2026, 17:54:16 UTC Added: 08/17/2026, 17:59:08 UTC |
0 compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request Forgery, targeting internal services or cloud metadata endpoints. Versions 3.12.2 and 4.0.3 fix the issue. Join the discussion | CVE Database V5 | 08/14/2026, 16:10:14 UTC Added: 08/14/2026, 16:27:44 UTC |
0 compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an attacker to achieve arbitrary command execution with privileges of the running process by injecting malicious payloads into data fields (such as SSP documents or Lookup Tables). The vulnerability does not require attacker control of the template itself. Only attacker-controlled input data rendered into a trusted template is required. This distinction is critical: the template author may only intend to render plain text (e.g., `Title: {{ ssp.metadata.title }}`), but because of the recursive parsing, the data field itself becomes executable. The vulnerability is caused by recursive re-compilation and re-rendering of already-rendered output. Versions 3.12.3 and 4.0.3 patch the issue. Join the discussion | CVE Database V5 | 08/14/2026, 16:08:08 UTC Added: 08/14/2026, 16:27:44 UTC |
A path traversal vulnerability (CWE-22) exists in compliance-trestle's profile import mechanism prior to versions 3.12.3 and 4.0.3. The vulnerability allows crafted OSCAL profile YAML files with malicious imports[].href values to read arbitrary files outside the intended workspace. The issue is fixed in versions 3.12.3 and 4.0.3. Join the discussion | CVE Database V5 | 08/13/2026, 19:26:44 UTC Added: 08/13/2026, 19:56:44 UTC |
0 compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences (`../`). When a remote OSCAL profile references a URL with traversal in its path, the HTTP response body is written to a location outside the intended cache directory, enabling arbitrary file write with attacker-controlled content to the filesystem. Versions 3.12.3 and 4.0.3 patch the issue. Join the discussion | CVE Database V5 | 08/13/2026, 19:22:59 UTC Added: 08/13/2026, 19:56:44 UTC |
Showing 1 to 6 of 6 results