These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,132 reserved CVEs with public mentions, ranked by all-time mention count.
Page 10 of 46
First seen Oct 9, 2026
CVE-2026-107381 is a case-sensitivity flaw in enshrined/svg-sanitize that allows nested SVG <use> structures to bypass denial-of-service protection. Resolver::processReferences() selects href attributes case-sensitively before Sanitizer::cleanHrefAttributes() normalizes their names. Mixed-case attributes therefore conceal references during reference collection, but those references become active in the sanitized output after normalization. Malicious SVG structures can consequently reach downstream renderers and potentially cause resource exhaustion.
CVE-2026-107381First seen Oct 9, 2026
CVE-2026-11713 affects IBM WebSphere Application Server Liberty versions earlier than 26.0.0.10. The vulnerability's technical mechanism, affected function, and specific exploitation consequences are currently unavailable.
CVE-2026-11713First seen Oct 8, 2026
CVE-2026-77816 affects IBM WebSphere Application Server Liberty versions earlier than 26.0.0.10. The vulnerability type, affected function, exploitation mechanism, and CVE-specific impact are currently unavailable.
CVE-2026-77816First seen Oct 8, 2026
CVE-2026-65140 is a vulnerability affecting Slurm Workload Manager (slurm-wlm), a cluster resource management and job scheduling system. Affected distribution packages are identified for Ubuntu 22.04, 24.04, and 26.04 LTS and Debian 12, 13, and 14. Debian 13 (trixie) includes a fix in version 24.11.5-4+deb13u1. The underlying flaw, vulnerable function, and CVE-specific exploitation effects are not established.
CVE-2026-65140First seen Sep 4, 2026
CVE-2026-65108 is a vulnerability associated with Slurm Workload Manager (slurm-wlm), a cluster resource management and job scheduling system. Potentially affected packages include those for Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS, and Debian 12, 13, and 14. Debian 13 (trixie) includes a fix in version 24.11.5-4+deb13u1. The underlying flaw, vulnerable function, and precise affected-version ranges are currently not available.
CVE-2026-65108First seen Sep 4, 2026
CVE-2026-21120 is a use-after-free vulnerability in Samsung’s WSM service that could allow a local attacker to execute arbitrary code with system privileges. Samsung addressed the vulnerability in its October 2026 security update. The affected functions, precise triggering conditions, and affected software versions are not specified.
CVE-2026-21120First seen Oct 7, 2026
CVE-2026-79715 affects IBM WebSphere Application Server Liberty versions earlier than 26.0.0.10. Details of the vulnerability mechanism, affected functions, and CVE-specific impact are currently not available.
CVE-2026-79715First seen Oct 8, 2026
CVE-2026-14532 affects IBM WebSphere Application Server Liberty versions earlier than 26.0.0.10. The vulnerability's technical mechanism, affected component, and individual security impact are currently unavailable.
CVE-2026-14532First seen Oct 8, 2026
CVE-2026-21122 is a vulnerability in Samsung’s text-to-speech library that could allow a local attacker to execute arbitrary code. Samsung addressed the vulnerability in its October 2026 security update. The underlying defect, vulnerable function, and exact affected versions are not specified.
CVE-2026-21122First seen Oct 7, 2026
An out-of-bounds memory access vulnerability in the exllamav3_ext CUDA extension results from unchecked array indexing. Successful exploitation can cause immediate denial of service or application instability.
CVE-2026-84286First seen Sep 11, 2026
CVE-2025-58363 is a path traversal vulnerability in LF Edge eKuiper administrative plugin installation endpoints. Unsanitized, user-controlled plugin resource names permit deletion of arbitrary files and directories within the filesystem permissions of the eKuiper process. Exploitation can cause denial of service or disruption of the host environment. The vulnerability is delete-only and does not enable arbitrary file creation, modification, or code execution.
CVE-2025-58363First seen Sep 10, 2026
CVE-2026-65109First seen Sep 4, 2026
CVE-2026-103932 concerns improper PCRE2 error handling in ModSecurity's @rxGlobal operator. Reaching a regular-expression match limit can cause processing to fail open, allowing requests to bypass intended security checks. An invalid pattern can also crash the affected process. Assessment metadata associates the vulnerability with ModSecurity packages on Ubuntu and Debian, without specifying affected ModSecurity versions. The listed Amazon Linux 2, Amazon Linux 2023, and Amazon Linux 2027 Preview mod_security packages are explicitly identified as unaffected.
CVE-2026-103932First seen Oct 8, 2026
CVE-2026-65107 is a reported denial-of-service vulnerability affecting Slurm Workload Manager (slurm-wlm). Affected packages are listed for Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS, and Debian 12, 13, and 14. The vulnerable function, root cause, and triggering input are not specified. Debian includes this CVE in security update DSA-6491-1, with a fix for Debian 13 (trixie) in version 24.11.5-4+deb13u1.
CVE-2026-65107First seen Sep 4, 2026
CVE-2026-55453 is a vulnerability associated with the CUPS package on Debian Linux and included in Slackware advisory SSA:2026-278-01 for Slackware Linux 15.0 and -current. Debian Linux 12.0, 13.0, and 14.0 are listed in detection applicability metadata. The underlying flaw, vulnerable function, precise affected versions, and exploitation mechanism are not currently available.
CVE-2026-55453First seen Oct 6, 2026
CVE-2026-65138 affects Slurm Workload Manager (slurm-wlm), a cluster resource management and job scheduling system. Package detection metadata lists Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS, and Debian 12, 13, and 14 as affected releases. Debian security advisory DSA-6491-1 includes this vulnerability among seven issues addressed in version 24.11.5-4+deb13u1 for Debian stable (trixie), despite detection metadata describing the issue as unpatched. The root cause, vulnerable function, and exploitation mechanism are not specified.
CVE-2026-65138First seen Sep 4, 2026
CVE-2026-65139 is a vulnerability associated with the slurm-wlm package, which provides Slurm Workload Manager cluster resource management and job scheduling. Debian addressed it alongside six other vulnerabilities in security advisory DSA-6491-1, with a fix for Debian stable (trixie) in version 24.11.5-4+deb13u1. The specific weakness, vulnerable function, and exploitation mechanism are currently unavailable.
CVE-2026-65139First seen Sep 4, 2026
CVE-2026-41504 is a CRLF injection vulnerability in the Native audit-log formatter of Coraza versions 3.0.0 through 3.7.0. When Native formatting is used with Serial or Concurrent audit logging, attacker-controlled content is written without escaping carriage returns or line feeds. This permits forged lines within audit records, undermining their integrity and reliability. Request-body injection is reachable through the stock HTTP integration; header injection requires an integration that accepts unvalidated header bytes. JSON and OCSF audit-log formats are unaffected.
CVE-2026-41504First seen Oct 7, 2026
CVE-2026-14909 affects IBM WebSphere Application Server Liberty versions earlier than 26.0.0.10. The technical cause, vulnerable function, and exploitation mechanism are currently unspecified.
CVE-2026-14909First seen Oct 8, 2026
CVE-2026-104259 affects ModSecurity's t:removeComments transformation, which mishandles the character immediately following a comment terminator. This processing error allows a remote, unauthenticated attacker to bypass affected security rules without user interaction. Affected packages include modsecurity, modsecurity-apache, and Amazon Linux mod_security packages; precise vulnerable version ranges are not available.
CVE-2026-104259First seen Oct 8, 2026
CVE-2026-41508 affects multipart request-body processing in Coraza WAF versions 3.4.0 through 3.7.0. The parser silently handles io.ErrUnexpectedEOF from truncated multipart bodies without setting MULTIPART_STRICT_ERROR or propagating REQBODY_ERROR. Consequently, malformed requests bypass the recommended parsing-error rules 200003 and 200002. Differences between Coraza and backend multipart parsing may allow fields or payloads to evade security inspection. Version 3.8.0 fixes the vulnerability.
CVE-2026-41508First seen Oct 7, 2026
CVE-2026-97677 is a path traversal vulnerability in IBM Langflow OSS versions 1.0.0 through 1.12.2. An authenticated flow author can bypass local file access isolation and write attacker-controlled content into directories writable by the service account. A crafted on-disk index can also enable reading files accessible to that account, including secrets, configuration, and databases.
CVE-2026-97677First seen Oct 7, 2026
CVE-2026-21114 is an out-of-bounds write vulnerability in a Samsung media library affecting Android 14 through Android 17. A local attacker could exploit the flaw to execute arbitrary code. The vulnerability is addressed by Samsung's October 2026 security update; the specific vulnerable function and triggering input are not identified.
CVE-2026-21114First seen Oct 7, 2026
CVE-2026-104269 is a multipart filename security-rule bypass in ModSecurity. An RFC 2231 filename* parameter allows remote, unauthenticated attackers to bypass rules governing multipart filenames. Amazon Linux identifies mod_security as affected and pending a fix on Amazon Linux 2, 2023, and 2027 Preview, while httpd is not affected. Precise vulnerable package versions and the underlying implementation defect are not established.
CVE-2026-104269First seen Oct 8, 2026