1sealsemantic last-mile verification

Public research · coordinated disclosure

Research record

Browse records ↓

What we found in the layers everyone else's security depends on: signing, transparency, update frameworks, certificate validation, attestation, policy. Every record links to an upstream artifact — advisory, fix commit, release, or credit line. Source facts and researcher mappings are distinguished in each record; a public fix is not automatically public credit.

Records are evidence, not a unique vulnerability count.

more...

One finding may produce several records; one record may cover several findings. Finding IDs are mechanically deduplicated. The headline adds counted CVE/GHSA records, security PRs, credited fixes, reported fixes and hardening/testing records. Long-form write-ups live on Advisories, not as duplicate Research records. A finding documented only by a write-up remains here as a documented finding. Neither those rows nor historical fixes add headline records.

317counted public records
308finding IDs
149projects
10GHSAs published
29security-related PR records

Data revision 2026-09-26 (source checks are dated separately in details) · source portfolio.json · source digest d8b9c39f7975be56b62eead0ef9d72237f3f6ef46b006a0d7072732d35d5761e

Published snapshot; upstream changes are not checked here. Optional source-byte comparison requires JavaScript.

On this page

Highlights

Chosen for what they demonstrate, not for severity. Every one is externally verifiable upstream.

Three of 317 records. Browse the full corpus → · Research recognition

Security areas

Which security property is at issue? Select an area to browse its records, replacing previous filters.

311 of 322 records have a primary area.

more...

11 remain unassigned where source detail is insufficient or a contribution has no single affected property; reasons are retained in record evidence. These are editorial assessments of public evidence, not new vendor findings. This view counts records, so several records may concern the same finding.

Identity
43
Integrity
24
Provenance
9
Semantics
20
Authorization
93
Memory safety
41
Availability
66
Confidentiality
15

Failure mechanisms

How does the error happen? Select a mechanism to browse its records, replacing previous filters.

287 of 308 finding IDs have a recorded mechanism; 12 concern general hardening/testing; 9 need source detail.

more...

Related records sharing an ID count once here. These are editorial classifications, not new vendor assessments. Do not add the two views together. Overview counts stay global; selections open a filtered list in Browse records.

Verification failures
64
Access control
38
File / path escapes
31
Memory safety
38
Code / markup injection
10
Outbound request trust
15
Resource limits
30
Input / state handling
41
Secret handling
14
Display / action mismatch
6
General hardening / testing
12
Needs source detail
9

Browse records

322 of 322 records · 308 finding IDs

Group
Sort
6.1medium
CVE-2026-79705CVEpodman-container-tools/buildah

Local file overwrite by extracting a malicious tar archive

Fixed in: go.podman.io/buildah/copier 1.43.4 / 1.45.1

patched
details
Finding IDs
F-BUILDAH-SYMLINK-001
Status
patched
Fixed in
go.podman.io/buildah/copier 1.43.4 / 1.45.1
Recorded credit
reporter: Oleh Konko / @1seal (alongside other reporters)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

6.1medium
CVE-2025-11395CVEpodman-container-tools/container-libs

Local file overwrite by extracting a malicious tar archive

Fixed in: go.podman.io/image/v5 5.39.3 / 5.41.2; go.podman.io/storage 1.62.1 / 1.64.1

patched
details
Finding IDs
F-PODMAN-001-007
Status
patched
Fixed in
go.podman.io/image/v5 5.39.3 / 5.41.2; go.podman.io/storage 1.62.1 / 1.64.1
Recorded credit
reporter: Oleh Konko / @1seal (alongside other reporters)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.3medium
CVE-2026-65058CVEtrezor/trezor-firmware

Trezor Safe improper security check in on-device display

Fixed in: Trezor Safe 3, Safe 5, and Safe 7 (commit 70c9b0c)

patched
details
Finding IDs
F-TREZOR-005
Status
patched
Fixed in
Trezor Safe 3, Safe 5, and Safe 7 (commit 70c9b0c)
Recorded credit
Oleh Konko / 1seal

Full sources, classification reasons and claim limits are on the finding page.

5.5medium
CVE-2026-22703CVEsigstore/cosign

Verification accepts any valid Rekor entry under certain conditions

Fixed in: cosign v2.6.2, v3.0.4

patched
details
Finding IDs
F-SIG-036-001
Status
patched
Fixed in
cosign v2.6.2, v3.0.4
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.3medium
CVE-2026-23831CVEsigstore/rekor

COSE v0.0.1 entry type nil pointer dereference in Canonicalize via empty Message

Fixed in: rekor 1.5.0

patched
details
Finding IDs
F-SIG-038-001
Status
patched
Fixed in
rekor 1.5.0
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.3medium
CVE-2026-24117CVEsigstore/rekor

Server-Side Request Forgery (SSRF) via provided public key URL

Fixed in: rekor 1.5.0

patched
details
Finding IDs
F-REKOR-SSRF-001
Status
patched
Fixed in
rekor 1.5.0
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

3.7low
CVE-2026-24122CVEsigstore/cosign

Signatures considered valid with certificates that outlive expired CA certificates

Fixed in: cosign 3.0.5

patched
details
Finding IDs
F-COSIGN-001-003
Status
patched
Fixed in
cosign 3.0.5
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.8medium
CVE-2026-24137CVEsigstore/sigstore

Legacy TUF client allows for arbitrary file writes with target cache path traversal

Fixed in: sigstore 1.10.4

patched
details
Finding IDs
F-SIGSTORE-005
Status
patched
Fixed in
sigstore 1.10.4
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

6.5medium
CVE-2026-48816CVEsigstore/sigstore-js

Insufficient Verification of Data Authenticity in sigstore-js

Fixed in: @sigstore/verify 3.1.1

patched
details
Finding IDs
F-SIG-JS-TLOGTIME-001
Status
patched
Fixed in
@sigstore/verify 3.1.1
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.9medium
CVE-2026-23991CVEtheupdateframework/go-tuf/v2

Client DoS via malformed server response

Fixed in: go-tuf/v2 2.3.1

patched
details
Finding IDs
F-TUF-003
Status
patched
Fixed in
go-tuf/v2 2.3.1
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.9medium
CVE-2026-23992CVEtheupdateframework/go-tuf/v2

Improper validation of configured threshold for delegations

Fixed in: go-tuf/v2 2.3.1

patched
details
Finding IDs
F-TUF-001
Status
patched
Fixed in
go-tuf/v2 2.3.1
Upstream @1seal credit
@1seal: remediation_reviewer (accepted)

Full sources, classification reasons and claim limits are on the finding page.

8.1high
CVE-2026-24686CVEtheupdateframework/go-tuf/v2

go-tuf TAP 4 multirepo repoName path traversal escapes local metadata cache directory

Fixed in: go-tuf/v2 2.4.1

patched
details
Finding IDs
F-TUF-008
Status
patched
Fixed in
go-tuf/v2 2.4.1
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

6.5medium
CVE-2026-24845CVEchainguard-dev/malcontent

OCI image scanning could expose registry credentials

Fixed in: malcontent 1.20.3

patched
details
Finding IDs
F-MALCONTENT-003
Status
patched
Fixed in
malcontent 1.20.3
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.5medium
CVE-2026-24846CVEchainguard-dev/malcontent

Archive extraction could write outside extraction directory

Fixed in: malcontent 1.20.3

patched
details
Finding IDs
F-MALCONTENT-001
Status
patched
Fixed in
malcontent 1.20.3
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-25121CVEchainguard-dev/apko

Path traversal in apko dirFS allows filesystem writes outside base

Fixed in: apko (commit d8b7887)

patched
details
Finding IDs
F-APKO-001
Status
patched
Fixed in
apko (commit d8b7887)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-25140CVEchainguard-dev/apko

potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams

Fixed in: apko (commit 2be3903)

patched
details
Finding IDs
F-APKO-007
Status
patched
Fixed in
apko (commit 2be3903)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.5medium
CVE-2026-25122CVEchainguard-dev/apko

unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams

Fixed in: apko v1.1.0

patched
details
Finding IDs
F-APKO-003
Status
patched
Fixed in
apko v1.1.0
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-42574CVEchainguard-dev/apko

apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root

Fixed in: apko v1.2.5

patched
details
Finding IDs
F-APKO-SYMLINK-001
Status
patched
Fixed in
apko v1.2.5
Recorded credit
reporter: @1seal

Full sources, classification reasons and claim limits are on the finding page.

6.5medium
CVE-2026-42576CVEchainguard-dev/apko

apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery

Fixed in: apko v1.2.7

patched
details
Finding IDs
F-APKO-002
Status
patched
Fixed in
apko v1.2.7
Recorded credit
reporter: @1seal

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-42575CVEchainguard-dev/apko

apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)

Fixed in: apko v1.2.7

patched
details
Finding IDs
F-APKO-CHECKSUM-001
Status
patched
Fixed in
apko v1.2.7
Recorded credit
reporter: @1seal

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
CVE-2026-3833CVEgnutls/gnutls

Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison

Fixed in: GnuTLS 3.8.13

patched
details
Finding IDs
F-GNUTLS-NAMECONSTRAINTS-001
Status
patched
Fixed in
GnuTLS 3.8.13
Recorded credit
independently reported by Oleh Konko (1seal) and Joshua Rogers

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
CVE-2026-3832CVEgnutls/gnutls

Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response

Fixed in: GnuTLS 3.8.13

patched
details
Finding IDs
F-GNUTLS-OCSP-001
Status
patched
Fixed in
GnuTLS 3.8.13
Recorded credit
independently reported by Oleh Konko (1seal) and Joshua Rogers

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
CVE-2026-42012CVEgnutls/gnutls

Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans

Fixed in: GnuTLS 3.8.13

patched
details
Finding IDs
F-GNUTLS-HOSTNAME-001
Status
patched
Fixed in
GnuTLS 3.8.13
Recorded credit
reported by Oleh Konko (1seal)

Full sources, classification reasons and claim limits are on the finding page.

7.9high
CVE-2026-24844CVEchainguard-dev/melange

Pipeline working-directory could allow command injection

Fixed in: melange (commit e51ca30c)

patched
details
Finding IDs
F-MELANGE-001
Status
patched
Fixed in
melange (commit e51ca30c)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

8.2high
CVE-2026-24843CVEchainguard-dev/melange

QEMU runner could write files outside workspace directory

Fixed in: melange (commit 6e243d0d)

patched
details
Finding IDs
F-MELANGE-005
Status
patched
Fixed in
melange (commit 6e243d0d)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.8high
CVE-2026-25143CVEchainguard-dev/melange

potential host command execution via license-check YAML mode patch pipeline

Fixed in: melange (commit bd132535)

patched
details
Finding IDs
F-MELANGE-007
Status
patched
Fixed in
melange (commit bd132535)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.5medium
CVE-2026-25145CVEchainguard-dev/melange

path traversal in `license-path` allows reading files outside workspace

Fixed in: melange (commit 2f95c9f)

patched
details
Finding IDs
F-MELANGE-006
Status
patched
Fixed in
melange (commit 2f95c9f)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.9medium
CVE-2026-25518CVEcert-manager/cert-manager

cert-manager-controller DoS via Specially Crafted DNS Response

Fixed in: cert-manager v1.18.5, v1.19.3

patched
details
Finding IDs
F-CERTMGR-DNS-001
Status
patched
Fixed in
cert-manager v1.18.5, v1.19.3
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.9medium
CVE-2026-26189CVEaquasecurity/trivy-action

script injection via sourced env file in composite action

Fixed in: trivy-action >= 0.34.0

patched
details
Finding IDs
F-TRIVY-ACTION-001
Status
patched
Fixed in
trivy-action >= 0.34.0
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
CVE-2026-27589CVEcaddyserver/caddy

cross-origin config application via local admin API /load (caddy)

Fixed in: caddy v2.11.0

patched
details
Finding IDs
F-CADDY-ADMIN-LOAD-001
Status
patched
Fixed in
caddy v2.11.0
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

4.9medium
CVE-2026-22728CVEbitnami-labs/sealed-secrets

sealed-secrets /v1/rotate can widen sealing scope to cluster-wide via attacker-controlled template annotations

Fixed in: sealed-secrets v0.36.0

patched
details
Finding IDs
F-SEALED-SECRETS-ROTATE-SCOPE-001
Status
patched
Fixed in
sealed-secrets v0.36.0
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-29054CVEtraefik/traefik

Case-Sensitive Bypass in Connection Header Allows Removal of X-Forwarded Headers

Upstream fixed versions: Traefik: v2.11.38; Traefik: v3.6.9

patched
details
Finding IDs
F-TRAEFIK-003
Status
patched
Fixed in
Traefik: v2.11.38; Traefik: v3.6.9
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-26999CVEtraefik/traefik

TLS Handshake Error Handling Allows Stalled Connections on TCP Routers

Upstream fixed versions: Traefik: v2.11.38; Traefik: v3.6.9

patched
details
Finding IDs
F-TRAEFIK-004
Status
patched
Fixed in
Traefik: v2.11.38; Traefik: v3.6.9
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

8.7high
CVE-2026-29777CVEtraefik/traefik

Kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values

Fixed in: v3.6.10

patched
details
Finding IDs
F-TRAEFIK-006
Status
patched
Fixed in
v3.6.10
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
GHSA-3jrg-j22w-mpmcGHSAaws/aws-lc

AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN

Fixed in: AWS-LC 1.71.0

patched
details
Finding IDs
F-AWS-LC-NAMECONSTRAINTS-001 / F-AWS-LC-NAMECONSTRAINTS-002
Status
patched
Fixed in
AWS-LC 1.71.0
Upstream @1seal credit
No structured @1seal credit in this snapshot; textual acknowledgements may exist.

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
GHSA-394x-vwmw-crm3GHSAaws/aws-lc-rs

AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN

Fixed in: aws-lc-sys 0.39.0

patched
details
Finding IDs
F-AWS-LC-NAMECONSTRAINTS-001 / F-AWS-LC-NAMECONSTRAINTS-002
Status
patched
Fixed in
aws-lc-sys 0.39.0
Upstream @1seal credit
No structured @1seal credit in this snapshot; textual acknowledgements may exist.

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
GHSA-x4cm-pcq4-39j4GHSAgetsops/sops

Path traversal in `sops exec-file --filename` leaks decrypted plaintext outside temporary directory

Fixed in: sops 3.13.0

patched
details
Finding IDs
F-MOZILLA-SOPS-002
Status
patched
Fixed in
sops 3.13.0
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
GHSA-jgf3-f6rg-8x3hGHSAgetsops/sops

HC Vault / OpenBao token exfiltration when decrypting untrusted SOPS-encrypted files

mitigation available; configuration required
details
Finding IDs
F-MOZILLA-SOPS-004
Status
mitigation available; configuration required
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
GHSA-vhvq-fv9f-wh4qGHSAauthzed/spicedb

LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic

Fixed in: spicedb v1.49.1

patched
details
Finding IDs
F-AUTHZED-SPICEDB-001
Status
patched
Fixed in
spicedb v1.49.1
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

4.4medium
CVE-2026-93602CVErustls/webpki

CRLs not considered authoritative by Distribution Point due to faulty matching logic

Fixed in: 0.104.0-alpha.5, 0.103.10

patched
details
Finding IDs
F-RUSTLS-WEBPKI-001
Status
patched
Fixed in
0.104.0-alpha.5, 0.103.10
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

2.2low
CVE-2026-93601CVErustls/webpki

Name constraints were accepted for certificates asserting a wildcard name

Fixed in: >= 0.103.12, >= 0.104.0-alpha.6

patched
details
Finding IDs
F-RUSTLS-WEBPKI-NAMECONSTRAINTS-WILDCARD-001
Status
patched
Fixed in
>= 0.103.12, >= 0.104.0-alpha.6
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.3medium
CVE-2026-35468CVEnimiq/core-rs-albatross

Panic in history index request handlers when a full node runs without the history index

Fixed in: nimiq-blockchain v1.3.0

patched
details
Finding IDs
F-NIMIQ-HISTORYINDEX-PANIC-001
Status
patched
Fixed in
nimiq-blockchain v1.3.0
Recorded credit
finder: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

4.3medium
CVE-2026-40094CVEnimiq/core-rs-albatross

Untrusted peer can crash address book via empty peer contact addresses

Fixed in: nimiq-network-libp2p v1.4.0

patched
details
Finding IDs
F-NIMIQ-DISCOVERY-EMPTY-ADDRLIST-PANIC-001
Status
patched
Fixed in
nimiq-network-libp2p v1.4.0
Recorded credit
finder: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.3medium
CVE-2026-44505CVEnimiq/core-rs-albatross

Untrusted peer can wedge DHT

Fixed in: network-libp2p v1.4.0

patched
details
Finding IDs
F-NIMIQ-DHTGET-HANG-001
Status
patched
Fixed in
network-libp2p v1.4.0
Recorded credit
finder: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-34063CVEnimiq/core-rs-albatross

Peer can crash the node by opening discovery protocol substream twice

Fixed in: network-libp2p v1.3.0

patched
details
Finding IDs
F-NIMIQ-DISCOVERY-DOUBLE-SUBSTREAM-PANIC-001
Status
patched
Fixed in
network-libp2p v1.3.0
Recorded credit
finder: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.3medium
CVE-2026-34062CVEnimiq/core-rs-albatross

nimiq-libp2p request/response codec reads entire stream before size validation

Fixed in: network-libp2p v1.3.0

patched
details
Finding IDs
F-NIMIQ-REQRES-STREAMS-STALL-001
Status
patched
Fixed in
network-libp2p v1.3.0
Recorded credit
finder: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-9064CVE389ds/389-ds-base

389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos)

affected
details
Finding IDs
F-FREEIPA-389DS-001
Status
affected
Recorded credit
Red Hat acknowledgement: Oleh Konko (1seal.org)

Full sources, classification reasons and claim limits are on the finding page.

0.0low
GHSA-w5f8-87h2-m573GHSAnimiq/core-rs-albatross

Request/Response inbound failure retains stale `response_channels` state after attacker-controlled failed requests

Fixed in: nimiq-network-libp2p v1.3.0

patched
details
Finding IDs
F-NIMIQ-REQRES-INBOUNDLEAK-001
Status
patched
Fixed in
nimiq-network-libp2p v1.3.0
Recorded credit
finder: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.9medium
CVE-2026-46539CVEnimiq/core-rs-albatross

BlockInclusionProof interlink issue when hops are empty

Fixed in: nimiq-primitives v1.4.0

patched
details
Finding IDs
F-NIMIQ-BLOCKINCLUSIONPROOF-INTERLINK-HOPS-001
Status
patched
Fixed in
nimiq-primitives v1.4.0
Recorded credit
finder: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
CVE-2026-34073CVEpyca/cryptography

X.509: bypass of name constraints on wildcard SANs with matching peer names

Fixed in: >= 46.0.6

patched
details
Finding IDs
F-PYCA-CRYPTOGRAPHY-NAMECONSTRAINTS-WILDCARD-001
Status
patched
Fixed in
>= 46.0.6
Recorded credit
Reporter: 1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.1high
CVE-2026-28457CVEopenclaw/openclaw

Sandbox skill mirroring path traversal could write outside the sandbox workspace

Fixed in: openclaw >= 2026.2.14

patched
details
Finding IDs
F-OPENCLAW-001
Status
patched
Fixed in
openclaw >= 2026.2.14
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.7high
CVE-2026-31801CVEproject-zot/zot

create-only policy allows overwrite attempts of existing latest tag (update permission not required)

Upstream fixed versions: zot: v2.1.15

patched
details
Finding IDs
F-ZOT-AUTHZ-001
Status
patched
Fixed in
zot: v2.1.15
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

8.7high
CVE-2026-31837CVEistio/istio

JWKS Resolver Failure May Expose Hardcoded Default Keys

Fixed in: 1.29.1, 1.28.5, 1.27.8

patched
details
Finding IDs
F-ISTIO-JWKS-002
Status
patched
Fixed in
1.29.1, 1.28.5, 1.27.8
Recorded credit
reported by 1seal (ISTIO-SECURITY-2026-001)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

6.9medium
CVE-2026-31838CVEistio/istio

Debug Endpoints Allow Cross-Namespace Proxy Data Access

Fixed in: 1.29.1, 1.28.5, 1.27.8

patched
details
Finding IDs
F-ISTIO-XDSDEBUG-002
Status
patched
Fixed in
1.29.1, 1.28.5, 1.27.8
Recorded credit
reported by 1seal (ISTIO-SECURITY-2026-001)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.0medium
CVE-2026-41413CVEistio/istio

SSRF via RequestAuthentication jwksUri

Fixed in: 1.29.2, 1.28.6

patched
details
Finding IDs
F-ISTIO-JWKS-001
Status
patched
Fixed in
1.29.2, 1.28.6
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
CVE-2026-28407CVEchainguard-dev/malcontent

Nested archive extraction failure can drop content from scan inputs

Fixed in: malcontent v1.21.0

patched
details
Finding IDs
F-MALCONTENT-010
Status
patched
Fixed in
malcontent v1.21.0
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

9.6critical
CVE-2026-33211CVEtektoncd/pipeline

Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod

Fixed in: v1.0.1, v1.3.3, v1.6.1, v1.9.2, v1.10.2

patched
details
Finding IDs
F-TEKTON-001-001
Status
patched
Fixed in
v1.0.1, v1.3.3, v1.6.1, v1.9.2, v1.10.2
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-3547CVEwolfSSL/wolfssl

wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation

Fixed in: wolfSSL 5.9.0

patched
details
Finding IDs
F-WOLFSSL-ALPN-001
Status
patched
Fixed in
wolfSSL 5.9.0
Recorded credit
thanks to Oleh Konko (1seal) for the report (wolfSSL v5.9.0-stable release note)

Full sources, classification reasons and claim limits are on the finding page.

8.3high
CVE-2026-3549CVEwolfSSL/wolfssl

ECH parsing heap buffer overflow

Fixed in: wolfSSL 5.9.0

patched
details
Finding IDs
F-WOLFSSL-ECH-001
Status
patched
Fixed in
wolfSSL 5.9.0
Recorded credit
thanks to Oleh Konko (1seal) for testing (wolfSSL v5.9.0-stable release note)

Full sources, classification reasons and claim limits are on the finding page.

7.0high
CVE-2026-5263CVEwolfSSL/wolfssl

URI nameConstraints not enforced in ConfirmNameConstraints()

Fixed in: wolfSSL 5.9.1

patched
details
Finding IDs
F-WOLFSSL-NC-URI-001
Status
patched
Fixed in
wolfSSL 5.9.1
Recorded credit
finder: Oleh Konko @1seal (wolfSSL CNA / v5.9.1-stable release note)

Full sources, classification reasons and claim limits are on the finding page.

6.5medium
CVE-2026-33022CVEtektoncd/pipeline

Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun

Upstream fixed versions: github.com/tektoncd/pipeline: 1.0.1, 1.3.3, 1.6.1, 1.9.2, 1.10.2

patched
details
Finding IDs
F-TEKTON-PANIC-001
Status
patched
Fixed in
github.com/tektoncd/pipeline: 1.0.1, 1.3.3, 1.6.1, 1.9.2, 1.10.2
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

6.5medium
CVE-2026-25542CVEtektoncd/pipeline

VerificationPolicy regex pattern bypass via substring matching

Upstream fixed versions: github.com/tektoncd/pipeline: 1.0.2, 1.3.4, 1.6.2, 1.9.3, 1.11.1

patched
details
Finding IDs
F-TEKTON-REGEX-001
Status
patched
Fixed in
github.com/tektoncd/pipeline: 1.0.2, 1.3.4, 1.6.2, 1.9.3, 1.11.1
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.3medium
GHSA-54p8-x2m9-c593GHSAchainguard-dev/malcontent

Error-path cleanup gap can leak scanners and fds and degrade availability

Fixed in: malcontent v1.21.0

patched
details
Finding IDs
F-MALCONTENT-006
Status
patched
Fixed in
malcontent v1.21.0
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

4.9medium
CVE-2026-34061CVEnimiq/core-rs-albatross

Macro block proposal interlink bug

Fixed in: nimiq-blockchain v1.3.0

patched
details
Finding IDs
F-NIMIQ-INTERLINK-001
Status
patched
Fixed in
nimiq-blockchain v1.3.0
Recorded credit
finder: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

6.8medium
CVE-2026-34068CVEnimiq/core-rs-albatross

`UpdateValidator` transactions allows voting key change without proof-of-knowledge

Fixed in: v1.3.0

patched
details
Finding IDs
F-NIMIQ-ROGUEKEY-001
Status
patched
Fixed in
v1.3.0
Recorded credit
finder: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-34065CVEnimiq/core-rs-albatross

Peer-triggerable crash via invalid election macro validators voting key hashing announced macro blocks

Fixed in: v1.3.0

patched
details
Finding IDs
F-NIMIQ-VALIDATORSKEY-PANIC-001
Status
patched
Fixed in
v1.3.0
Recorded credit
finder: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

8.2high
CVE-2026-28406CVEchainguard-forks/kaniko

tar archive path traversal in build context extraction allows writing files outside destination directory

Upstream fixed versions: package name not specified: no patched version listed

unpatched
details
Finding IDs
F-CHAINGUARD-FORKS-KANIKO-AG5-001
Status
unpatched
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

4.3medium
CVE-2026-29049CVEchainguard-dev/melange

unbounded HTTP download in `melange update-cache` can exhaust disk in CI

Upstream fixed versions: package name not specified: v0.43.4

patched
details
Finding IDs
F-MELANGE-003
Status
patched
Fixed in
package name not specified: v0.43.4
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

6.1medium
CVE-2026-29050CVEchainguard-dev/melange

Path traversal in melange's external pipeline resolver (pipeline[].uses) allows loading a pipeline from outside the pipeline directories

Fixed in: melange v0.43.4

patched
details
Finding IDs
F-MELANGE-008
Status
patched
Fixed in
melange v0.43.4
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

4.4medium
CVE-2026-29051CVEchainguard-dev/melange

Path traversal in melange --persist-lint-results via unvalidated .PKGINFO fields

Fixed in: melange v0.43.4

patched
details
Finding IDs
F-MELANGE-004
Status
patched
Fixed in
melange v0.43.4
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
CVE-2026-21518CVEmicrosoft/vscode

Workspace trust for MCP servers

Fixed in: VS Code 1.109.1

patched
details
Finding IDs
F-VSCODE-MCP-001
Status
patched
Fixed in
VS Code 1.109.1
Upstream @1seal credit
No structured @1seal credit in this snapshot; textual acknowledgements may exist.

Full sources, classification reasons and claim limits are on the finding page.

8.0high
CVE-2026-21523CVEmicrosoft/vscode

GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability

Fixed in: VS Code 1.110.1; VS Code Copilot Chat Extension 0.37.1

patched
details
Finding IDs
F-VSCODE-COPILOT-001
Status
patched
Fixed in
VS Code 1.110.1; VS Code Copilot Chat Extension 0.37.1
Recorded credit
MSRC acknowledgement: Oleh Konko with 1seal

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
CVE-2026-3842CVEqemu/qemu

Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write

Fixed in: upstream commit 4f28b87fdd24

patched
details
Finding IDs
F-QEMU-001-001
Status
patched
Fixed in
upstream commit 4f28b87fdd24
Recorded credit
Reported-by: Oleh Konko <https://github.com/1seal>

Full sources, classification reasons and claim limits are on the finding page.

8.8high
CVE-2026-34040CVEmoby/moby

AuthZ plugin bypass with oversized request body

Upstream fixed versions: Docker Engine: 29.3.1

patched
details
Finding IDs
F-MOBY-001-001
Status
patched
Fixed in
Docker Engine: 29.3.1
Recorded credit
1seal / Oleh Konko (@1seal)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-33540CVEdistribution/distribution

Pull-through cache credential exfiltration via www-authenticate bearer realm

Upstream fixed versions: distribution: >=3.1.0

patched
details
Finding IDs
F-DIST-PROXY-SSRF-001
Status
patched
Fixed in
distribution: >=3.1.0
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-35172CVEdistribution/distribution

Stale blob access resurrection via repo-scoped redis descriptor cache invalidation

Upstream fixed versions: package name not specified: >=3.1.0

patched
details
Finding IDs
F-DIST-REDIS-REVIVAL-001
Status
patched
Fixed in
package name not specified: >=3.1.0
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-29181CVEopen-telemetry/opentelemetry-go

multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

Upstream fixed versions: go.opentelemetry.io/otel/baggage: v1.41.0; go.opentelemetry.io/otel/propagation: v1.41.0

patched
details
Finding IDs
F-OTELGO-001
Status
patched
Fixed in
go.opentelemetry.io/otel/baggage: v1.41.0; go.opentelemetry.io/otel/propagation: v1.41.0
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.3medium
CVE-2026-39882CVEopen-telemetry/opentelemetry-go

OTLP HTTP exporters read unbounded HTTP response bodies

Upstream fixed versions: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp: v1.43.0; go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp: v1.43.0; go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp: v0.19.0

patched
details
Finding IDs
F-OTELGO-002
Status
patched
Fixed in
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp: v1.43.0; go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp: v1.43.0; go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp: v0.19.0
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.3medium
CVE-2026-40182CVEopen-telemetry/opentelemetry-dotnet

OTLP exporter reads unbounded HTTP response bodies

Fixed in: 1.15.2

patched
details
Finding IDs
F-OTELGO-002
Status
patched
Fixed in
1.15.2
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

4.8medium
CVE-2026-35206CVEhelm/helm

Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment

Fixed in: 3.20.2, 4.1.4

patched
details
Finding IDs
F-HELM-UNTAR-ROOT-COLLAPSE-001
Status
patched
Fixed in
3.20.2, 4.1.4
Recorded credit
Oleh Konko (@1seal)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

3.7low
CVE-2026-40097CVEsmallstep/certificates

Index out-of-bounds panic via crafted AK certificate with empty EKU in TPM device attestation

Fixed in: v0.30.0

patched
details
Finding IDs
F-SMALLSTEP-AK-EKU-001
Status
patched
Fixed in
v0.30.0
Recorded credit
Oleh Konko (@1seal)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-32605CVEnimiq/core-rs-albatross

Remote crash via off-by-one signer bounds check in proposal buffer

Fixed in: v1.3.0

patched
details
Finding IDs
F-NIMIQ-PROPOSAL-001
Status
patched
Fixed in
v1.3.0
Recorded credit
finder: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

8.1high
CVE-2026-40868CVEkyverno/kyverno

kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token

Fixed in: 1.16.4

patched
details
Finding IDs
F-KYVERNO-APICALL-001
Status
patched
Fixed in
1.16.4
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

9.8critical
CVE-2026-54334CVEtheopolis/uefi-firmware-parser

Heap out-of-bounds write in tiano decompressor `ReadCLen`

Fixed in: CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)

patched
details
Finding IDs
F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003
Status
patched
Fixed in
CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

9.8critical
CVE-2026-54333CVEtheopolis/uefi-firmware-parser

Stack out-of-bounds write in tiano decompressor MakeTable

Fixed in: CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)

patched
details
Finding IDs
F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002
Status
patched
Fixed in
CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

4.1medium
GHSA-pmwq-pjrm-6p5rGHSAin-toto/in-toto-golang

Inconsistent negation behavior between in-toto-golang and in-toto-python

Fixed in: in-toto-golang v0.11.0

patched
details
Finding IDs
F-INTOTO-CROSS-IMPL-001
Status
patched
Fixed in
in-toto-golang v0.11.0
Recorded credit
finder: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-4525CVEhashicorp/vault

Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header

Fixed in: 2.0.0, 1.21.5, 1.20.10, 1.19.16

patched
details
Finding IDs
F-VAULT-AUTHZ-BEARER-TOKEN-LEAK-001
Status
patched
Fixed in
2.0.0, 1.21.5, 1.20.10, 1.19.16
Recorded credit
identified and reported by Oleh Konko of 1seal (HCSEC-2026-07)

Full sources, classification reasons and claim limits are on the finding page.

5.3medium
CVE-2026-5052CVEhashicorp/vault

Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS

Fixed in: Vault CE 2.0.0; Vault Enterprise 2.0.0, 1.21.5, 1.20.10, 1.19.16

patched
details
Finding IDs
F-VAULT-ACME-SSRF-001
Status
patched
Fixed in
Vault CE 2.0.0; Vault Enterprise 2.0.0, 1.21.5, 1.20.10, 1.19.16
Recorded credit
independently identified and reported by Oleh Konko of 1seal (HCSEC-2026-06)

Full sources, classification reasons and claim limits are on the finding page.

7.7high
CVE-2026-2092CVEkeycloak/keycloak

Keycloak: Unauthorized access via improper validation of encrypted SAML assertions

Fixed in: 26.2.14, 26.4.10, 26.5.5, 26.6.0

patched
details
Finding IDs
F-KEYCLOAK-SAML-001
Status
patched
Fixed in
26.2.14, 26.4.10, 26.5.5, 26.6.0
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

4.7medium
CVE-2026-6550CVEaws/aws-encryption-sdk-python

Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python

Fixed in: 3.3.1, 4.0.5

patched
details
Finding IDs
F-AWS-ENCRYPTION-SDK-PYTHON-001
Status
patched
Fixed in
3.3.1, 4.0.5
Recorded credit
acknowledgement: 1seal.org
Upstream @1seal credit
No structured @1seal credit in this snapshot; textual acknowledgements may exist.

Full sources, classification reasons and claim limits are on the finding page.

7.7high
CVE-2026-5190CVEaws/aws-sdk-cpp

Memory Corruption in event-stream parsing of headers

Fixed in: aws-c-event-stream 0.6.0; aws-sdk-cpp 1.11.764

patched
details
Finding IDs
F-AWS-EVENT-STREAM-001
Status
patched
Fixed in
aws-c-event-stream 0.6.0; aws-sdk-cpp 1.11.764
Recorded credit
acknowledgement: Oleh Konko from 1seal / 1seal.org
Upstream @1seal credit
No structured @1seal credit in this snapshot; textual acknowledgements may exist.

Full sources, classification reasons and claim limits are on the finding page.

5.9medium
CVE-2026-89090CVEaws/aws-sdk-go-v2

Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder

Fixed in: aws/protocol/eventstream v1.7.8; service-specific versions listed in the advisory

patched
details
Finding IDs
F-AWS-SDK-GO-V2-ES-001
Status
patched
Fixed in
aws/protocol/eventstream v1.7.8; service-specific versions listed in the advisory
Recorded credit
reporter: @1seal (accepted); AWS acknowledgement: Oleh Konko (@1seal)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.3medium
CVE-2026-6966CVEawslabs/tough

Signature Threshold Bypass in awslabs/tough Delegated Roles

Fixed in: tough 0.22.0, tuftool 0.15.0

patched
details
Finding IDs
F-AWS-TOUGH-001
Status
patched
Fixed in
tough 0.22.0, tuftool 0.15.0
Recorded credit
reporter: @1seal; acknowledgement: Oleh Konko of 1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.9medium
CVE-2026-6967CVEawslabs/tough

Missing Delegated Metadata Validation in awslabs/tough

Fixed in: tough 0.22.0, tuftool 0.15.0

patched
details
Finding IDs
F-AWS-TOUGH-002 / F-AWS-TOUGH-003 / F-AWS-TOUGH-004 / F-AWS-TOUGH-005
Status
patched
Fixed in
tough 0.22.0, tuftool 0.15.0
Recorded credit
reporter: @1seal; acknowledgement: Oleh Konko of 1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

5.9medium
CVE-2026-6968CVEawslabs/tough

Multiple Path Traversal Variants in awslabs/tough

Fixed in: tough 0.22.0, tuftool 0.15.0

patched
details
Finding IDs
F-AWS-TOUGH-007 / F-AWS-TOUGH-008 / F-AWS-TOUGH-009
Status
patched
Fixed in
tough 0.22.0, tuftool 0.15.0
Recorded credit
reporter: @1seal; acknowledgement: Oleh Konko of 1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.6high
CVE-2026-5068CVEzephyrproject-rtos/zephyr

bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data

Fixed in: main PR #104913, v4.3 PR #108335; v3.7 backport pending

patched
details
Finding IDs
F-ZEPHYR-BLE-001
Status
patched
Fixed in
main PR #104913, v4.3 PR #108335; v3.7 backport pending
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
CVE-2026-48978CVEoras-project/oras-go

Bearer realm URL not validated, enabling SSRF to internal networks and TLS downgrade

Fixed in: oras-go v2.7.0

patched
details
Finding IDs
F-ORAS-AUTH-001
Status
patched
Fixed in
oras-go v2.7.0
Recorded credit
@1seal credited as Analyst; advisory says reported by bugbunny.ai
Upstream @1seal credit
@1seal: analyst (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
CVE-2026-50151CVEoras-project/oras-go

credential forwarding via unvalidated Location header in oras-go blob upload

Upstream fixed versions: https://github.com/oras-project/oras-go: v2.6.2

patched
details
Finding IDs
F-ORAS-LOCATION-UPLOAD-001
Status
patched
Fixed in
https://github.com/oras-project/oras-go: v2.6.2
Recorded credit
reporter: @1seal
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

7.5high
GHSA-54w7-rw44-49m7GHSAelement-hq/element-x-ios

io.element.call deeplink allows attacker-controlled HTTPS origin and may grant mic/camera to that origin

Fixed in: Element X iOS 26.05.0

CVE-2026-55644: RESERVED; not counted as a published CVE

patched
details
Finding IDs
F-ELEMENTX-IOS-001
Status
patched
Fixed in
Element X iOS 26.05.0
Upstream @1seal credit
No structured @1seal credit in this snapshot; textual acknowledgements may exist.

Full sources, classification reasons and claim limits are on the finding page.

5.9medium
CVE-2026-48497CVEenvoyproxy/envoy

Abnormal process termination in DNS UDP filter

Fixed in: Envoy 1.35.12, 1.36.8, 1.37.4, 1.38.2

patched
details
Finding IDs
F-ENVOY-001-002
Status
patched
Fixed in
Envoy 1.35.12, 1.36.8, 1.37.4, 1.38.2
Recorded credit
finder: @1seal
Upstream @1seal credit
@1seal: finder (accepted)

Full sources, classification reasons and claim limits are on the finding page.

8.8high
CVE-2026-43334CVEtorvalds/linux

Bluetooth: SMP: force responder MITM requirements before building the pairing response

Fixed in: Linux 7.0; stable backports listed in the CNA record; mainline d05111bfe37bfd8bd4d2dfe6675d6bdeef43f7c7

patched
details
Finding IDs
F-TORVALDS-LINUX-BT-SMP-001
Status
patched
Fixed in
Linux 7.0; stable backports listed in the CNA record; mainline d05111bfe37bfd8bd4d2dfe6675d6bdeef43f7c7
Recorded credit
Upstream commit author and Signed-off-by: Oleh Konko / 1seal; no credit field in the Linux CNA record.

Full sources, classification reasons and claim limits are on the finding page.

8.8high
CVE-2026-31773CVEtorvalds/linux

Bluetooth: SMP: derive legacy responder STK authentication from MITM state

Fixed in: Linux 7.0; stable backports listed in the CNA record; mainline 20756fec2f0108cb88e815941f1ffff88dc286fe

patched
details
Finding IDs
F-TORVALDS-LINUX-BT-SMP-001
Status
patched
Fixed in
Linux 7.0; stable backports listed in the CNA record; mainline 20756fec2f0108cb88e815941f1ffff88dc286fe
Recorded credit
Upstream commit author and Signed-off-by: Oleh Konko / 1seal; no credit field in the Linux CNA record.

Full sources, classification reasons and claim limits are on the finding page.

8.1high
CVE-2026-31771CVEtorvalds/linux

Bluetooth: hci_event: move wake reason storage into validated event handlers

Fixed in: Linux 7.0; stable backports listed in the CNA record; mainline 2b2bf47cd75518c36fa2d41380e4a40641cc89cd

patched
details
Finding IDs
F-TORVALDS-LINUX-BT-HCI-001
Status
patched
Fixed in
Linux 7.0; stable backports listed in the CNA record; mainline 2b2bf47cd75518c36fa2d41380e4a40641cc89cd
Recorded credit
Upstream commit author and Signed-off-by: Oleh Konko / 1seal; no credit field in the Linux CNA record.

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
CVE-2026-50162CVEoras-project/oras-go

file store write outside workingDir via symlink traversal in oras-go

Fixed in: CVE record: 2.6.1; GHSA: 2.6.2 (conflicting version metadata)

patched
details
Finding IDs
F-ORAS-SYMLINK-WRITE-001
Status
patched
Fixed in
CVE record: 2.6.1; GHSA: 2.6.2 (conflicting version metadata)
Recorded credit
reporter: @1seal (accepted, repository GHSA)
Upstream @1seal credit
@1seal: reporter (accepted)

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
theopolis/uefi-firmware-parser #145Credited fixtheopolis/uefi-firmware-parser

Apply hardening fixes from upstream Tiano implementation

merged
details
Finding IDs
F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003 / F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002
Status
merged
Recorded credit
PR body: "Thank you @1seal for mentioning this!"

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
spiffe/spireCredited fixspiffe/spire

http_challenge SSRF fixed in v1.14.2 and v1.13.4

released
details
Finding IDs
F-SPIRE-HTTPCHALLENGE-001
Status
released
Recorded credit
Thank you, Oleh Konko (@1seal) for reporting this issue. also credited in v1.13.4 and CHANGELOG.md.

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
npm/cliReported fixnpm/cli

Global executable ownership check accepts a prefix-colliding package directory

Fixed in: bin-links 6.0.1; also verified in npm 11.15.0 (bin-links 6.0.2)

fixed publicly
details
Finding IDs
F-NPM-CLI-001
Status
fixed publicly
Fixed in
bin-links 6.0.1; also verified in npm 11.15.0 (bin-links 6.0.2)

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
facebook/docusaurusReported fixfacebook/docusaurus

Deployment branch text is reinterpreted as Git command arguments

Fixed in: main and 4.0.0-canary-6848; stable 3.10.2 still uses the old command path

merged to main/pre-release only
details
Finding IDs
F-DOCUSAURUS-DEPLOY-ARGINJECT-001
Status
merged to main/pre-release only
Fixed in
main and 4.0.0-canary-6848; stable 3.10.2 still uses the old command path

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
facebook/proxygenReported fixfacebook/proxygen

Binary HTTP field-section length includes its own prefix

Fixed in: main fix commit; v2026.09.21.00 still contains the old parser

fixed on main (release not confirmed)
details
Finding IDs
F-PROXYGEN-BINARYHTTP-001
Status
fixed on main (release not confirmed)
Fixed in
main fix commit; v2026.09.21.00 still contains the old parser

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
WhatsApp/waraftReported fixWhatsApp/waraft

Snapshot transport accepts file paths outside its destination root

Fixed in: public source commit; a separate fixed release is not established

fixed on main (release not confirmed)
details
Finding IDs
F-WHATSAPP-WARAFT-001
Status
fixed on main (release not confirmed)
Fixed in
public source commit; a separate fixed release is not established

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
ProtonVPN/android-appReported fixProtonVPN/android-app

Exported activity accepts actions intended for internal VPN widgets

Fixed in: 5.19.72.0 source and release; installed store binaries not reverified

fixed publicly
details
Finding IDs
F-PROTON-VPN-ANDROID-GLANCE-001
Status
fixed publicly
Fixed in
5.19.72.0 source and release; installed store binaries not reverified

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
protonpass/ios-authenticatorReported fixprotonpass/ios-authenticator

Authenticator processes OTP deep links before completing local authentication

Fixed in: 1.4.0 source tag; App Store delivery not independently verified

fixed publicly
details
Finding IDs
F-PROTON-IOS-AUTH-001
Status
fixed publicly
Fixed in
1.4.0 source tag; App Store delivery not independently verified

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
ProtonDriveApps/android-driveReported fixProtonDriveApps/android-drive

Deep-link upload path omits external URI validation

Fixed in: 2.40.0 source tag; also present in the later 3.0.0 source release

fixed publicly
details
Finding IDs
F-PROTON-DRIVE-DEEPLINK-001
Status
fixed publicly
Fixed in
2.40.0 source tag; also present in the later 3.0.0 source release

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
ProtonWallet/flutter-appReported fixProtonWallet/flutter-app

Recovery and wallet import logging includes mnemonic words

Fixed in: v1.3.0+115 source tag; store rollout not independently verified

fixed publicly
details
Finding IDs
F-PROTON-WALLET-FLUTTER-001
Status
fixed publicly
Fixed in
v1.3.0+115 source tag; store rollout not independently verified

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
bcgit/bc-javaReported fixbcgit/bc-java

Ambiguous multi-at-sign mailbox evades excluded email name constraints

Fixed in: Java 1.85 and C# 2.7.0, with default strict email-name parsing

fixed publicly
details
Finding IDs
F-BC-NC-MULTIAT-001
Status
fixed publicly
Fixed in
Java 1.85 and C# 2.7.0, with default strict email-name parsing

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
ggml-org/whisper.cppReported fixggml-org/whisper.cpp

Model tensor dimension count can exceed a four-element stack array

Fixed in: verified in v1.9.4; not asserted to be the first fixed version

fixed publicly
details
Finding IDs
F-WHISPER-001-002
Status
fixed publicly
Fixed in
verified in v1.9.4; not asserted to be the first fixed version

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
neo-project/neoReported fixneo-project/neo

Notary-sponsored transaction fees are not bounded by the individual payer deposit

Fixed in: v3.10.1; network deployment not independently verified

fixed publicly
details
Finding IDs
F-NEO-NOTARY-001
Status
fixed publicly
Fixed in
v3.10.1; network deployment not independently verified

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
signalapp/libsignalReported fixsignalapp/libsignal

Failed message verification logs received and computed authentication tags

Fixed in: v0.103.0 library release; downstream application rollout not established

fixed publicly
details
Finding IDs
F-LIBSIGNAL-MAC-LOG-001
Status
fixed publicly
Fixed in
v0.103.0 library release; downstream application rollout not established

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
WireGuard/wireguard-windowsReported fixWireGuard/wireguard-windows

Configuration loader builds a path before validating the tunnel name

Fixed in: v1.1; recorded as defensive validation, not a confirmed reachable exploit

fixed publicly
details
Finding IDs
F-WIREGUARD-001-001
Status
fixed publicly
Fixed in
v1.1; recorded as defensive validation, not a confirmed reachable exploit

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
meta-llama/PurpleLlamaReported fixmeta-llama/PurpleLlama

Fix RCE for canary exploit

Fixed in: public source commit; a separate fixed release is not established

fixed on main (release not confirmed)
details
Finding IDs
F-PURPLELLAMA-003
Status
fixed on main (release not confirmed)
Fixed in
public source commit; a separate fixed release is not established

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
denoland/deno #33203Reported fixdenoland/deno

fix(permissions): check deny rules against resolved IPs to prevent numeric hostname bypass

fixed publicly in v2.7.12; Node compat follow-up in v2.8.0
details
Finding IDs
F-DENO-001-001
Status
fixed publicly in v2.7.12; Node compat follow-up in v2.8.0

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
ton-blockchain/tonReported fixton-blockchain/ton

arm RLDP receiver timeouts and validate FEC before receiver allocation

fixed in public source; rollout not reverified
details
Finding IDs
F-TON-006-001
Status
fixed in public source; rollout not reverified

Full sources, classification reasons and claim limits are on the finding page.

—score not recorded
envoyproxy/envoyReported fixenvoyproxy/envoy

uhv: use-after-free read in sanitizeHeadersWithUnderscores with duplicate underscore headers

fixed publicly via issue closure
details
Finding IDs
F-ENVOY-001-003
Status
fixed publicly via issue closure

Full sources, classification reasons and claim limits are on the finding page.

How to read a record

Recorded fields describe the portfolio mapping. Fields labelled upstream come from the linked advisory snapshot. Credit, release rollout and independent discovery are not inferred; omitted optional fields are not recorded.

Only CVEs confirmed PUBLISHED by the CVE registry count as CVEs. Reserved IDs stay pending. A published GHSA may count once as a GHSA while its CVE is pending; it does not add a second record.

patched
the source records a patch. A merged commit alone does not establish a released version or deployment.
fixed publicly
the record links to a public fix. This label alone does not establish vendor classification, reporter credit or rollout.
historical record
the source describes a pre-report fix or a historical mapping. Read its qualification; these rows are excluded from the headline.
accepted · pending
acceptance and publication are separate. Private reports are not added to this public corpus merely because they were accepted.

Method, attribution rules, and what we do about silent fixes: disclosure policy. Long-form 1seal write-ups are listed on Advisories.