Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:pypi/linuxfabrik-lib

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-73974 is a path traversal vulnerability in linuxfabrik monitoring-plugins prior to version 7.0.0 and linuxfabrik-lib prior to 6.1.0. The issue arises because the test helper function lib.lftest.test() improperly handles filesystem paths from a hidden --test argument, allowing unauthorized file reads without path confinement. This vulnerability enables an attacker with sudo-authorized plugin access to read arbitrary root-readable files. The flaw affects multiple plugins that expose file content or existence checks. The vulnerability is fixed by confining fixture reads to a safe directory and routing bypasses through the helper in the fixed versions.

Join the discussion

Linuxfabrik Monitoring Plugins and linuxfabrik-lib contain a local privilege escalation vulnerability due to unsafe command execution. User-controlled input is embedded in shell command strings that are split and executed, allowing injection of arbitrary commands. This affects versions prior to linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0. The vulnerability allows a compromised Nagios or Icinga account to execute commands as root via sudo. The issue is fixed by using argument lists, disabling shell command splitting, and sanitizing inputs.

Join the discussion

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 4.2.0, db_sqlite.py created SQLite databases at predictable paths in the shared /tmp directory and followed attacker-created symbolic links at those paths. An attacker who controls a local monitoring account can create a symlink such as /tmp/linuxfabrik-monitoring-plugins-docker-stats.db and then trigger a sudo-authorized plugin, causing the root process to create or modify the symlink target. The primitive can overwrite arbitrary paths, cause denial of service, or manipulate an existing SQLite database through a crafted rollback journal or write-ahead log. The Monitoring Plugins integration also moved plugin caches through lib.db_sqlite.get_db_path() so they use the secured per-user directory. This issue is fixed in version 4.2.0.

Join the discussion

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga account to execute /usr/bin/apt-get as root without restricting its arguments. An attacker who already controls that monitoring account can supply the APT::Update::Pre-Invoke option to execute an arbitrary command while apt-get runs with root privileges, resulting in a root shell and complete compromise of the host. The vulnerable rule supports the check-plugins/deb-updates/deb-updates plugin, but it authorized arbitrary apt-get argument sequences rather than only the required apt-get update --quiet 2 command. This issue is fixed in version 5.1.0.

Join the discussion

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 6.0.0, lib.url.fetch() followed cross-origin redirects while forwarding caller-supplied credential headers other than Authorization and Cookie, allowing a malicious redirect-capable server to receive headers such as X-Auth-Token from authenticated monitoring requests. This issue is fixed in version 6.0.0.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:pypi/linuxfabrik-lib
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses