---
title: 'Topic: cve'
canonical_url: https://portal.chinng-lab-srv.dev/topics/cve.md
content_kind: topic
updated_at: '2026-08-02T07:21:57Z'
---

# Topic: cve

> Stable topic monitoring page generated from normalized published metadata.

- Canonical: https://portal.chinng-lab-srv.dev/topics/cve.md
- Last updated: 2026-08-02T07:21:57Z
- Search: https://portal.chinng-lab-srv.dev/api/search?q=cve
- MCP: portal_search(q="cve")

## Related categories

- security/library
- security/os

## Related entities

- GitPython
- Latvia
- GitHub
- Chainguard
- Incomplete_Aesthetics
- Gotosocial_injection
- New edge AI module based on Blackwell architecture that enables humaninoid robot mass production
- CVE-2026-44243
- addcustomemojis
- Code Pink
- Ter Haibin Airport Bombing<br
- HigherDose
- MCP
- Herme's Dashboard Basic Authentication User
- HorrorWriters
- local
- Threads
- Charles Hudson
- SparseAutoencoder
- Python REPL

## Latest articles

- [GHSA-94p4-4cq8-9g67: GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)](https://portal.chinng-lab-srv.dev/security/library/security-20260725-df0150.md): GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
- [GHSA-r9mr-m37c-5fr3: GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution](https://portal.chinng-lab-srv.dev/security/library/security-20260725-d05ab6.md): GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
- [GHSA-6p8h-3wgx-97gf: GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks](https://portal.chinng-lab-srv.dev/security/library/security-20260725-96fd04.md): GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
- [GHSA-fjr4-x663-mwxc: GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)](https://portal.chinng-lab-srv.dev/security/library/security-20260725-aa9760.md): GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
- [GHSA-3rp5-jjmw-4wv2: GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)](https://portal.chinng-lab-srv.dev/security/library/security-20260725-bc7367.md): GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
- [CVE-2026-61632: PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path](https://portal.chinng-lab-srv.dev/security/library/security-20260725-6eddf9.md): PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
- [CVE-2026-59821: LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks](https://portal.chinng-lab-srv.dev/security/library/security-20260724-cfd1d4.md): LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
- [CVE-2026-59200: Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()](https://portal.chinng-lab-srv.dev/security/library/security-20260724-bc2416.md): Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
- [CVE-2026-59822: LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback](https://portal.chinng-lab-srv.dev/security/library/security-20260724-819d64.md): LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
- [CVE-2026-59820: LiteLLM: Arbitrary file write via path traversal in Skills archive extraction](https://portal.chinng-lab-srv.dev/security/library/security-20260724-5fecae.md): LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
- [CVE-2026-59204: Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service](https://portal.chinng-lab-srv.dev/security/library/security-20260724-51d556.md): Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
- [CVE-2026-59819: LiteLLM: Local file read via request-supplied OIDC file references](https://portal.chinng-lab-srv.dev/security/library/security-20260724-34de13.md): LiteLLM: Local file read via request-supplied OIDC file references
- [CVE-2026-59198: Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images](https://portal.chinng-lab-srv.dev/security/library/security-20260724-a8f0ed.md): Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
- [CVE-2026-54058: Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)](https://portal.chinng-lab-srv.dev/security/library/security-20260724-2a8214.md): Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
- [CVE-2026-59950: MCP Python SDK: WebSocket server transport does not support Host/Origin validation](https://portal.chinng-lab-srv.dev/security/library/security-20260724-2aafed.md): MCP Python SDK: WebSocket server transport does not support Host/Origin validation
- [CVE-2026-52869: MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal](https://portal.chinng-lab-srv.dev/security/library/security-20260724-270802.md): MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
- [CVE-2026-52870: MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks](https://portal.chinng-lab-srv.dev/security/library/security-20260724-13fb1a.md): MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
- [CVE-2026-59821: LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks](https://portal.chinng-lab-srv.dev/security/library/security-20260723-537f58.md): LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
- [CVE-2026-59822: LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback](https://portal.chinng-lab-srv.dev/security/library/security-20260723-9fd6c7.md): LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
- [CVE-2026-59819: LiteLLM: Local file read via request-supplied OIDC file references](https://portal.chinng-lab-srv.dev/security/library/security-20260723-c85540.md): LiteLLM: Local file read via request-supplied OIDC file references
- [CVE-2026-59820: LiteLLM: Arbitrary file write via path traversal in Skills archive extraction](https://portal.chinng-lab-srv.dev/security/library/security-20260723-65e0c5.md): LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
- [CVE-2026-67322: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL](https://portal.chinng-lab-srv.dev/security/library/security-20260722-bdbe76.md): GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
- [CVE-2026-67323: GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`](https://portal.chinng-lab-srv.dev/security/library/security-20260722-f9f263.md): GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
- [CVE-2026-67325: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist](https://portal.chinng-lab-srv.dev/security/library/security-20260722-96cbaf.md): GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
- [CVE-2026-59890: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+](https://portal.chinng-lab-srv.dev/security/library/security-20260722-ba03c4.md): setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
- [CVE-2026-59205: Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch](https://portal.chinng-lab-srv.dev/security/library/security-20260721-9c81bc.md): Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
- [CVE-2026-59204: Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service](https://portal.chinng-lab-srv.dev/security/library/security-20260721-e02209.md): Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
- [CVE-2026-59203: Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service](https://portal.chinng-lab-srv.dev/security/library/security-20260721-941bc6.md): Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
- [CVE-2026-59200: Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()](https://portal.chinng-lab-srv.dev/security/library/security-20260721-3aa418.md): Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
- [CVE-2026-59199: Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow](https://portal.chinng-lab-srv.dev/security/library/security-20260721-ca974b.md): Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
- [CVE-2026-59198: Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images](https://portal.chinng-lab-srv.dev/security/library/security-20260721-48da14.md): Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
- [CVE-2026-59197: Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`](https://portal.chinng-lab-srv.dev/security/library/security-20260721-871179.md): Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
- [CVE-2026-55798: Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path](https://portal.chinng-lab-srv.dev/security/library/security-20260721-054ec0.md): Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
- [CVE-2026-55380: Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`](https://portal.chinng-lab-srv.dev/security/library/security-20260721-4fa7c9.md): Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
- [CVE-2026-55379: Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading](https://portal.chinng-lab-srv.dev/security/library/security-20260721-d74706.md): Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
- [CVE-2026-54060: Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`](https://portal.chinng-lab-srv.dev/security/library/security-20260721-a1dd3d.md): Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
- [CVE-2026-54059: Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading](https://portal.chinng-lab-srv.dev/security/library/security-20260721-f6d04d.md): Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
- [CVE-2026-54058: Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)](https://portal.chinng-lab-srv.dev/security/library/security-20260721-6fab85.md): Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
- [CVE-2026-59950: MCP Python SDK: WebSocket server transport does not support Host/Origin validation](https://portal.chinng-lab-srv.dev/security/library/security-20260717-da152e.md): MCP Python SDK: WebSocket server transport does not support Host/Origin validation
- [CVE-2026-52869: MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal](https://portal.chinng-lab-srv.dev/security/library/security-20260717-f4f0b5.md): MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
- [CVE-2026-52870: MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks](https://portal.chinng-lab-srv.dev/security/library/security-20260717-e2a08b.md): MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
- [DEBIAN-CVE-2026-60005 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260718-ff4471.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens…
- [DEBIAN-CVE-2026-56434 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260719-649a91.md): NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directiv…
- [DEBIAN-CVE-2026-42533 — nginx](https://portal.chinng-lab-srv.dev/security/os/security-20260719-3eea23.md): A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map out…
- [CVE-2026-59197 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260723-e5b374.md): Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilt…
- [CVE-2026-59203 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260716-a3f93e.md): Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file…
- [CVE-2026-59205 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260716-51776c.md): Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image wh…
- [CVE-2026-59199 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260716-ec2875.md): Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in…
- [GHSA-xf7x-x43h-rpqh: json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS](https://portal.chinng-lab-srv.dev/security/library/security-20260714-fc7931.md): json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
- [CVE-2026-47102: LiteLLM allows a user to modify their own user_role via the /user/update endpoint](https://portal.chinng-lab-srv.dev/security/library/security-20260714-af08b2.md): LiteLLM allows a user to modify their own user_role via the /user/update endpoint
