Advisories
Found by Cipher, fixed upstream.
Original vulnerabilities Cipher reported in widely deployed open-source and embedded software: identity infrastructure, a 5G core, data platforms, building automation, and the tools developers live in. Each row links to its upstream advisory. New entries publish as embargoes lift.
← Field reports & writeups Advisory ledger Ordered by severity, then date · Latest entry Sep 9, 2026
- OpenEMRCVSS 9.9 CWE-89 affected < 8.3.0 fixed 8.3.0 Aug 18, 2026
- StackGres
- authentikHigh Signature checked, audience and reuse not: a SAML assertion signs in as its subjectCVSS 7.4 CWE-287 affected ≤ 2026.2.6, ≤ 2026.5.6, ≤ 2026.8.1 fixed 2026.2.7, 2026.5.7, 2026.8.2 Sep 9, 2026
- strongSwan
- OpenMRS FHIR2CVSS 7.5 CWE-862 affected 4.0.0 fixed 4.1.0 Aug 20, 2026
- Hasura GraphQL
- GraphicsMagick
- ZITADEL
- ZITADELCVE-2026-55672 CVSS 7.4 CWE-287 affected 4.0.0-4.15.1, 3.0.0-3.4.11 fixed 4.15.2, 3.4.12 Jun 17, 2026
- YamcsModerate Telemetry denied over REST, streamed over WebSocket
- BACnet StackModerate One WriteGroup packet reaches a pre-auth out-of-bounds read
- CVSS 6.5 CWE-125 affected ≤ 26.01 fixed 26.02 Jun 25, 2026
- Supabase Realtime