Threats Tagged 'cve-2026-59995'
View all threats tagged with 'cve-2026-59995'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-59995'
Click on any threat for detailed analysis and mitigation recommendations
PostgreSQL is an advanced object-relational database management system (DBMS). Security Fix(es): * postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662) * postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464) * postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471) * postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments (CVE-2026-14680) * postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664) * postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677) * postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound (CVE-2026-15742) * postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle (CVE-2026-16239) * postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation (CVE-2026-14669) * postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation (CVE-2026-14679) * postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module (CVE-2026-14671) * postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow (CVE-2026-14670) * postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator (CVE-2026-14668) * postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists (CVE-2026-19385) * postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse (CVE-2026-15741) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/24/2026, 11:59:15 UTC Added: 09/15/2026, 01:37:48 UTC |
OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server. Security Fix(es): * openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995) * openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999) * openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282) Bug Fix(es) and Enhancement(s): * Incomplete backport of CVE-2023-38408 in RHEL 8 openssh (JIRA:RHEL-234763) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/21/2026, 13:28:03 UTC Added: 07/21/2026, 20:02:50 UTC |
0 This update includes the following RPMs: openssh: * openssh-10.4p1-1.hum1 (aarch64, x86_64) * openssh-askpass-10.4p1-1.hum1 (aarch64, x86_64) * openssh-clients-10.4p1-1.hum1 (aarch64, x86_64) * openssh-keycat-10.4p1-1.hum1 (aarch64, x86_64) * openssh-keysign-10.4p1-1.hum1 (aarch64, x86_64) * openssh-server-10.4p1-1.hum1 (aarch64, x86_64) * openssh-sk-dummy-10.4p1-1.hum1 (aarch64, x86_64) * openssh-10.4p1-1.hum1.src (src) Join the discussion | GCVE Database | 07/09/2026, 14:40:15 UTC Added: 07/10/2026, 09:25:27 UTC |
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server. Join the discussion | CVE Database V5 | 07/08/2026, 00:04:49 UTC Added: 07/08/2026, 00:58:54 UTC |
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS). Join the discussion | GCVE Database | 06/23/2026, 06:30:41 UTC Added: 07/21/2026, 20:02:50 UTC |
Showing 1 to 5 of 5 results