CVE-2026-71556 CVE-2026-71556: Symbolic Link Directory Traversal in go-git A symbolic link directory traversal vulnerability was identified in go-git, a pure Go implementation of the Git specification. This vulnerability allows an attacker to construct a repository that, when checked out or processed, bypasses directory boundaries to write or overwrite arbitrary files on the host filesystem.

Channel
Daily CVE Reports
@cvereports
On this record: Growth · Engagement · Posts · Cite this entry
44subscribers
+0 since we began measuring on 7 August 2026
Risers and fallers across the register · movement among entries of Under 1,000.
Register entry
| Telegram ID | -1002615251780 |
|---|---|
| Type | Channel |
| Username | @cvereports |
| Created | Between 1 March 2025 and 31 July 2025 — estimated from Telegram’s id allocation, not measured. How this range is calculated. |
| First recorded | 10 August 2026 |
| Last confirmed live | 6 September 2026 |
| Measurements held | 4 |
| Confirmed unchanged | 2 times, most recently 6 September 2026 |
| On Telegram | t.me/cvereports |
Growth
| Measured (UTC) | Subscribers | Change |
|---|---|---|
| 30 Aug 2026, 03:05 | 44 | -1 |
| 22 Aug 2026, 21:42 | 45 | +1 |
| 10 Aug 2026, 15:46 | 44 | no change |
| 7 Aug 2026, 20:43 | 44 | first reading |
Engagement
20 posts held, back to 7 August 2026 — the reader has not yet reached the start of this channel’s public history, so older posts may sit further back, unread. Read across 1 page of Telegram’s post history, 20 posts per page.
Nothing published in the last 30 days. ERR and ER are rolling 30-day measures, so there is nothing to compute — we hold 20 posts for this entry, the most recent from 8 August 2026. An engagement rate over an empty window would be a number about nothing.
Recent posts
CVE-2026-71557 CVE-2026-71557: Path Traversal and Configuration Overwrite in go-git Filesystem Storage Engine CVE-2026-71557 is a path traversal vulnerability in go-git, a pure-Go implementation of Git. In vulnerable versions, the filesystem-backed storage engine fails to validate reference names before mapping them to on-disk paths. An attacker hosting a malicious Git server can advertise references containing dir…
GHSA-7C4V-FWGW-9RF7 GHSA-7c4v-fwgw-9rf7: Nuxt Dev Server Discloses Project Root and Workspace UUID via Chrome DevTools Endpoint An information disclosure vulnerability in the Nuxt development server allows adjacent network attackers to retrieve the absolute project root directory and a persistent workspace UUID by querying the unprotected Chrome DevTools workspace endpoint. This occurs when the development server i…
CVE-2026-66062 CVE-2026-66062: Regular Expression Denial of Service (ReDoS) in SvelteKit Content Negotiation A Regular Expression Denial of Service (ReDoS) vulnerability exists in SvelteKit's content negotiation header parser prior to version 2.70.2. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted Accept header with highly repetitive malformed values. This triggers catastrophi…
CVE-2026-15895 CVE-2026-15895: OS Command Injection in AWS jsii-diff CLI An OS command injection vulnerability exists in the npm package loading component of the jsii-diff CLI tool within the AWS jsii framework. Prior to version 1.131.0, when parsing package specifiers prefixed with `npm:`, the tool concatenated user-controlled inputs directly into a shell execution string via child_process.exec. This allows attack…
CVE-2026-63220 CVE-2026-63220: Trust of Untrusted Reverse Proxy Headers in CodeIgniter4 CodeIgniter4 versions prior to v4.7.4 contain a protocol-spoofing vulnerability due to improper verification of upstream reverse proxy forwarding headers. Remote, unauthenticated attackers can inject headers like X-Forwarded-Proto to deceive the framework into identifying an insecure HTTP request as a secure HTTPS connection.
CVE-2026-63221 CVE-2026-63221: SQL Injection in CodeIgniter4 Query Builder deleteBatch() An SQL injection vulnerability exists in the Query Builder component of the CodeIgniter4 full-stack PHP framework. The vulnerability is located within the compilation logic of the batch delete operation, deleteBatch(). When an application chains where() conditions prior to calling deleteBatch(), the Query Builder fails to enfor…
CVE-2026-63222 CVE-2026-63222: Remote Code Execution via Path Traversal in CodeIgniter4 File Upload Handler CVE-2026-63222 details a high-severity path traversal vulnerability in CodeIgniter4 versions prior to 4.7.4. The flaw lies within the `UploadedFile::move()` handler, which falls back to unsanitized, client-provided file names from the HTTP multipart request when a target name is not explicitly passed. An unau…
CVE-2026-63223 CVE-2026-63223: Unrestricted File Upload leading to Remote Code Execution in CodeIgniter4 A critical unrestricted file upload vulnerability (CWE-434) in CodeIgniter4 allows unauthenticated remote attackers to execute arbitrary code. By bypassing weak validation filters in the `is_image` and `mime_in` rules, an attacker can upload a malicious PHP payload disguised as a valid image file.
CVE-2026-67422 CVE-2026-67422: Regular Expression Denial of Service in pymdown-extensions A high-severity Regular Expression Denial of Service (ReDoS) vulnerability in pymdown-extensions versions prior to 11.0.1 affects the Caret, Tilde, BetterEm, and MagicLink inline processors. When parsing user-supplied Markdown content containing malicious sequences of formatting delimiters, the regular expression engine is for…
CVE-2026-71847 CVE-2026-71847: Use-After-Free in Ruby JSON Gem ResumableParser A technical analysis of the use-after-free (UAF) vulnerability in the Ruby JSON gem (CVE-2026-71847) that impacts versions 2.20.0 through 2.21.1. This vulnerability occurs when parsing incomplete stream data containing duplicate keys.
CVE-2026-71848 CVE-2026-71848: Algorithmic Complexity Denial of Service in Hono languageDetector Middleware An Algorithmic Complexity Denial of Service (DoS) vulnerability exists in the Hono web application framework within its languageDetector middleware. From version 4.12.0 to 4.12.33, the progressive language-tag truncation routine (normalizeLanguage) performs string operations with a quadratic time complexity O…
Showing the 12 most recent of 20 posts we hold for @cvereports. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.
Cite this entry
A live page changes as we take new readings, so a citation should name the measurement it is based on, not just the URL. The line below cites the subscriber count as measured 30 August 2026 — this entry's latest reading, not the date you are reading this.
“Daily CVE Reports” (@cvereports), 44 subscribers as measured 30 August 2026. Telegram Register, tgregister.com/channel/cvereports.
Full measurement history, CC BY 4.0. Every reading this register holds for this entry, not just the latest one, as a dated, downloadable record: CSV · JSON. Free to use with attribution to tgregister.com. Each file carries its own generation timestamp, which is the figure to cite for exactly when the data was retrieved.