CVE Tools
Back to feed
Patch released next (npm) rce sharp (npm) Next.js auth-bypass

Four Critical CVEs, the Same Trust Issue

OX Security·By Moshe Siman Tov Bustan, Nir Zadok··4 min read

Last week, 4 unauthenticated critical CVEs turned up in 24 hours, all sharing the same mistake: a component trusting the layer next to it

Within a single 24-hour window last week, four critical vulnerabilities landed across widely deployed infrastructure: two in Next.js, one in Netty, one in GitPython. All four are remotely reachable, all four require no authentication, and three of the four sit in code paths that are on by default.…

Continue reading on OX Security