|
1231
|
5.3 |
MEDIUM
Network
|
protobufjs_project
|
protobufjs protobufjs-cli
|
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobuf…
New
|
CWE-674 CWE-754
Uncontrolled Recursion Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-54269
|
2026-06-25 05:40 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1232
|
5.3 |
MEDIUM
Network
|
protobufjs_project
|
protobufjs
|
protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unknown wire elements in message.$unknowns and did not provide a decode-time option …
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-54270
|
2026-06-25 05:39 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1233
|
8.2 |
HIGH
Network
|
protobufjs_project
|
protobufjs-cli
|
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name handling in pbjs static / static-module code generation was incomplete. Affected ve…
New
|
CWE-94
Code Injection
|
CVE-2026-54271
|
2026-06-25 05:38 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1234
|
8.8 |
HIGH
Network
|
litellm
|
litellm
|
A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints.py of the component…
New
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-12770
|
2026-06-25 05:37 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1235
|
7.5 |
HIGH
Network
|
litellm
|
litellm
|
A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulatio…
New
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-12771
|
2026-06-25 05:31 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1236
|
6.3 |
MEDIUM
Network
|
litellm
|
litellm
|
A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database AP…
New
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-12772
|
2026-06-25 05:28 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1237
|
9.8 |
CRITICAL
Network
|
litellm
|
litellm
|
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the compone…
New
|
CWE-287
Improper Authentication
|
CVE-2026-12773
|
2026-06-25 05:27 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1238
|
6.3 |
MEDIUM
Network
|
litellm
|
litellm
|
A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-12774
|
2026-06-25 05:24 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1239
|
7.3 |
HIGH
Network
|
litellm
|
litellm
|
A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executin…
New
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-12795
|
2026-06-25 05:15 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1240
|
6.3 |
MEDIUM
Network
|
litellm
|
litellm
|
A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_openid of the file litellm/proxy/management_endpoints/ui_sso.py of the component S…
New
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-12796
|
2026-06-25 05:13 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|