Development & Open Source
Software development and open source follows supply chain, dependencies, tooling, repositories and code security. The cluster highlights vulnerabilities, updates and useful practices for developers and maintainers.

NGINX Rift and Fragnesia: Two Critical Flaws at the Heart of Internet Infrastructure
An 18-year-old heap overflow hits nearly 19 million NGINX servers with unauthenticated RCE, while a local Linux exploit corrupts the p…

GStreamer RCE Flaw in rtpsbcdepay Codec: Patch Available
ZDI-26-467 (CVE-2026-18299) details a use-after-free in GStreamer's RTP SBC depayloader enabling remote code execution. The primary ri…

CVE-2026-6100: CPython Use-After-Free in Decompressors Rated CVSS 9.1 Critical
CVE-2026-6100 affects CPython with a use-after-free in the lzma, bz2, and gzip decompressors. The CVSS 4.0 score is 9.1 CRITICAL, thou…

Aeon RCE via Pickle Dataset: ML Pipeline Risk
CVE-2026-18285: The Python library Aeon executed arbitrary code through pickle deserialization of seemingly legitimate datasets. The b…

AsyncAPI: Five npm Packages Compromised with Valid Provenance
Attackers hijacked the AsyncAPI project's CI/CD pipeline on July 14, 2026, stealing the asyncapi-bot service account token and publish…

AI-Assisted Kernel Exploit: Researcher Publishes Root Escalation Code for Linux
STAR Labs researcher Lee Jia Jie has released exploit code for CVE-2026-53264, a use-after-free vulnerability in the Linux kernel's ne…

Aeon RCE Flaw in Benchmark Loading: The Risk Lies in the Datasets
Trend Micro's Zero Day Initiative published advisory ZDI-26-470 assigning CVE-2026-18287 to a code injection vulnerability in the Pyth…

GIMP: APNG Integer Overflow Enables Code Execution, Patch Released
An integer overflow in GIMP's APNG parser allows remote arbitrary code execution when a user opens a malicious file. Tracked as CVE-20…

GStreamer RCE Bug in MRF Parsing: Urgent Update Required
An out-of-bounds write vulnerability in GStreamer's MRF file parser enables remote code execution. User interaction is required, but t…

Tengu: The Botnet That Turns Reboot Into a Forensic Trap
Discovered by Nozomi Networks Labs, the Mirai variant Tengu abuses the hardware watchdog timer on embedded Linux devices to force an a…

OpenWrt: A '90s-Era Buffer Overflow Opens Routers to Remote Takeover
A critical flaw in OpenWrt's DHCPv6 server allows pre-authentication remote code execution on routers. A public proof-of-concept explo…

Samsung rlottie: RCE Bug in Lottie Animations, Patch Available Since July 3
The open-source Samsung rlottie library contains a numeric truncation vulnerability (CVE-2026-15551, CVSS 5.5) enabling remote code ex…