HighCVE-2026-39383 - Gotenberg webhook SSRFMay 2, 2026CVE-2026-39858 - Traefik forwarded alias auth bypassMay 2, 2026CVE-2026-42449 - n8n-mcp IPv4-mapped IPv6 SSRFMay 2, 2026CVE-2026-42786 - Bandit WebSocket fragment reassembly DoSMay 2, 2026CVE-2026-39804 - Bandit permessage-deflate decompression DoSMay 2, 2026CVE-2026-7039 - ssh-mcp description command injectionMay 2, 2026GHSA-v4p8-mg3p-g94g - LiteLLM MCP stdio command executionMay 2, 2026CVE-2026-40171 - Jupyter CommandLinker token theftMay 2, 2026GHSA-rpm5/GHSA-x2qx - GitPython command injectionMay 2, 2026GHSA-rh99-wc69-c255 - Contrast CopyFile policy symlink subversionMay 3, 2026CVE-2026-42461 - Arcane Compose template secret disclosureMay 2, 2026GHSA-74m3 - zrok WebDAV DriveRoot symlink escapeMay 2, 2026CVE-2026-41485 - Kyverno forEach mutation panic DoSMay 3, 2026CVE-2026-42349 - Clerk combined authorization bypassMay 3, 2026