These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,133 reserved CVEs with public mentions, ranked by all-time mention count.
Page 27 of 46
First seen Sep 3, 2026
First seen Sep 3, 2026
First seen Sep 3, 2026
First seen Sep 3, 2026
First seen Sep 3, 2026
CVE-2026-54697 affects org.connectbot.sshlib:sshlib through version 0.3.0. Its DER private-key parser inadequately validates DER length fields. Crafted length values can cause integer wraparound during parsing and lead to excessive memory allocation. The resulting allocation failure can raise an uncaught OutOfMemoryError and terminate the affected application process. The issue is also associated with CWE-789 (uncontrolled memory allocation).
CVE-2026-54697First seen Jul 9, 2026
NLTK contains an argument-injection flaw in per-call JVM option handling used by GenericStanfordParser, StanfordTagger, StanfordTokenizer, and StanfordSegmenter. User-supplied java_options passed to nltk.internals.java() are not validated when supplied through the per-call options parameter, bypassing JVM-option validation. An attacker who controls this value can introduce arbitrary JVM arguments, including options that load Java or native agents, enable remote debugging, or cause additional argument files to be processed.
CVE-2026-12615First seen Sep 2, 2026
First seen Sep 1, 2026
First seen Sep 1, 2026
First seen Sep 1, 2026
First seen Sep 1, 2026
First seen Sep 1, 2026
First seen Sep 1, 2026
First seen Sep 1, 2026
First seen Sep 1, 2026
First seen Sep 1, 2026
First seen Aug 31, 2026
First seen Aug 31, 2026
First seen Aug 31, 2026
First seen Aug 31, 2026
First seen Aug 30, 2026
First seen Aug 30, 2026
First seen Aug 28, 2026
First seen Aug 28, 2026
First seen Aug 28, 2026