These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,132 reserved CVEs with public mentions, ranked by all-time mention count.
Page 11 of 46
CVE-2017-1135 is a vulnerability in the RadAsyncUpload component of Telerik UI for ASP.NET AJAX, where user input is used directly without validation, resulting in an insecure direct object reference. This flaw allows attackers to upload arbitrary files to a restricted location on the server, potentially leading to remote code execution. The vulnerability is related to cryptographic weaknesses and unrestricted file upload issues, and is associated with other vulnerabilities such as CVE-2019-18935 and the Blue Mockingbird campaign.
CVE-2017-1135First seen Oct 5, 2026
CVE-2026-12074 is a path traversal vulnerability in Natural Language Toolkit (NLTK)'s FramenetCorpusReader.frame() method. Attacker-controlled input can cause XML files outside the intended corpus root to be read, bypassing the nltk.pathsec sandbox even when ENFORCE=True. Related doc() and lexical-unit loading code paths may also be reachable through a malicious or attacker-modified FrameNet corpus index. The vulnerability is fixed in NLTK 3.10.0.
CVE-2026-12074First seen Aug 1, 2026
CVE-2026-61813 concerns a weak libcurl TLS hostname-verification setting when fetching resources over HTTPS. The Debian modsecurity-apache package is identified as affected on Debian Linux 12.0, 13.0, and 14.0. Inadequate hostname verification can allow acceptance of a TLS certificate that does not authenticate the intended server hostname. The precise setting, vulnerable function, and affected package-version boundaries are not available.
CVE-2026-61813First seen Oct 1, 2026
CVE-2026-53615 is an integer overflow vulnerability in the DOS partition-table parser of libblkid, part of util-linux. Processing a crafted block-device image may trigger the vulnerability and cause denial of service. The specific vulnerable function and affected upstream version range are not established.
CVE-2026-53615First seen Jun 18, 2026
CVE-2026-12876 is an uncontrolled resource consumption vulnerability in NLTK's RecursiveDescentParser and SteppingRecursiveDescentParser. Processing ambiguous or left-recursive context-free grammars can cause unbounded CPU consumption or Python recursion-stack exhaustion. An attacker who can supply a grammar or input to an affected parser can cause denial of service in the parsing process.
CVE-2026-12876First seen Sep 4, 2026
CVE-2026-73857 concerns dereferencing an uninitialized parser context pointer in the mod_security XML request body processor, with potential denial-of-service consequences. Debian Linux 12.0, 13.0, and 14.0 are listed as affected, although affected mod_security versions are not specified. The listed mod_security packages for Amazon Linux 2 Core, Amazon Linux 2023, and Amazon Linux 2027 Preview are explicitly marked not affected.
CVE-2026-73857First seen Oct 1, 2026
CVE-2026-48002 affects QEMU packages and is addressed by an Echo security update. It is also referenced in Oracle Linux 9 security advisory ELSA-2026-500220. The underlying flaw, affected function, and exploitation mechanism are currently not available.
CVE-2026-48002First seen Aug 24, 2026
CVE-2026-73856 is a response body inspection bypass in ModSecurity involving non-canonical Content-Type casing. Responses using such casing may evade body inspection, undermining response-side security enforcement. The affected ModSecurity versions and vulnerable function are not specified. The mod_security packages in Amazon Linux 2 Core, Amazon Linux 2023, and Amazon Linux 2027 Preview are identified as not affected.
CVE-2026-73856First seen Oct 1, 2026
CVE-2026-61812 is a security-filter evasion vulnerability in ModSecurity's HTML decoder. Missing support for HTML entities can allow encoded input to evade security filtering. An unauthenticated remote attacker could exploit the incomplete decoding to bypass filtering and affect integrity. The affected package is identified as mod_security on Amazon Linux and modsecurity-apache on Debian; Amazon Linux identifies httpd itself as unaffected.
CVE-2026-61812First seen Oct 1, 2026
CVE-2026-39043 affects gst-plugins-good1.0, part of the GStreamer media framework. It is addressed by a security update covering multiple vulnerabilities in plugins, codecs, and demuxers involving malformed media files. These vulnerabilities may cause denial of service or potentially arbitrary code execution. The specific defect, vulnerable function, and individual impact of CVE-2026-39043 are not established.
CVE-2026-39043First seen Jun 21, 2026
CVE-2026-8343 affects QEMU packages and is included in Oracle Linux 9 security advisory ELSA-2026-500220. The underlying flaw, vulnerable function, and exploitation mechanism are currently not available.
CVE-2026-8343First seen Aug 24, 2026
CVE-2026-16043 affects QEMU packages and is addressed by QEMU package updates, including Oracle Linux 9 security update ELSA-2026-500245. Technical details about the underlying flaw, vulnerable subsystem, and exploitation mechanism are currently not available.
CVE-2026-16043First seen Sep 8, 2026
CVE-2026-15578 affects QEMU packages and is associated with an availability impact. The vulnerable function, underlying weakness, triggering input, and affected version range are currently unavailable.
CVE-2026-15578First seen Sep 8, 2026
CVE-2026-12061 is a regular expression denial-of-service vulnerability in NLTK's ReviewsCorpusReader. The FEATURES regular expression exhibits quadratic backtracking when processing a crafted, long review line without brackets. This can hang reviews(), features(), and sents(), exhausting CPU resources and stalling applications that process attacker-controlled reviews corpora. NLTK 3.10.0 fixes the issue by bounding the per-label word run in the regular expression.
CVE-2026-12061First seen Aug 1, 2026
CVE-2026-39044 affects the GStreamer gst-plugins-good1.0 package. It belongs to a group of vulnerabilities in GStreamer plugins, codecs, and demuxers involving malformed media files that may cause denial of service or potentially arbitrary code execution when opened. The specific affected component, vulnerable function, root cause, and individual impact of CVE-2026-39044 are not established.
CVE-2026-39044First seen Jun 21, 2026
CVE-2026-9238 affects QEMU packages and is addressed by an Echo security update. It is also included in Oracle Linux 9 security advisory ELSA-2026-500220 alongside other QEMU vulnerabilities. Details of the underlying flaw, vulnerable function, affected-version range, and exploitation mechanism are currently unavailable.
CVE-2026-9238First seen Aug 24, 2026
CVE-2026-6425 affects QEMU packages and is also referenced in Oracle Linux 9 security advisory ELSA-2026-500220. The underlying weakness, vulnerable function, and exploitation mechanism are currently not available.
CVE-2026-6425First seen Aug 24, 2026
CVE-2026-12072 is a path traversal vulnerability in the Python Natural Language Toolkit (NLTK) NKJPCorpusReader. Insufficient validation of fileids accepted by its public read methods allows paths outside the intended corpus root to be accessed, bypassing nltk.pathsec sandbox protections even when enforcement is enabled. The header() method can directly disclose out-of-root file contents, while other reader methods can open and read such files.
CVE-2026-12072First seen Aug 1, 2026
CVE-2026-77913 is an out-of-bounds write vulnerability in QEMU's VGA text-mode display handling. The flaw occurs after a graphics-surface switch and can cause an out-of-bounds write during text-mode rendering.
CVE-2026-77913First seen Sep 30, 2026
CVE-2026-16271 is an improper input-validation issue in QEMU's QXL display-device handling. The flaw involves failure to validate a primary surface's stride against its width. Amazon Linux identifies the issue in the qemu package on Amazon Linux 2 Core; Amazon Linux 2023 and Amazon Linux 2027 Preview are listed as not affected.
CVE-2026-16271First seen Sep 30, 2026
CVE-2026-17588 is an important local vulnerability in QEMU's xHCI USB host-controller emulation component, hw/usb/hcd-xhci. The flaw involves a missing reentrancy guard in timer functions, which can permit unsafe reentrant execution in the emulated controller.
CVE-2026-17588First seen Sep 30, 2026
CVE-2026-96369First seen Sep 24, 2026
CVE-2026-84788 affects QEMU's io/channel-socket handling of zero-length writes. A zero-length write is treated as an error rather than handled as a non-error condition, resulting in incorrect exceptional-condition handling.
CVE-2026-84788First seen Sep 30, 2026
CVE-2026-66899First seen Sep 30, 2026
CVE-2026-66900 concerns QEMU's virtio-net device implementation when caching a Receive Segment Coalescing (RSC) segment. The associated fix strips trailing padding during RSC-segment caching. Available information does not establish the underlying vulnerability class, affected version range, or security impact.
CVE-2026-66900First seen Sep 30, 2026