These CVE IDs are still marked RESERVED at MITRE — no official description, no CVSS, no NVD record — yet the world is already talking about them. Mallory tracks the chatter so you see the risk before the paperwork catches up.
1,133 reserved CVEs with public mentions, ranked by all-time mention count.
Page 28 of 46
First seen Aug 27, 2026
First seen Aug 27, 2026
CVE-2026-61827 is an uncontrolled resource-consumption vulnerability in the Netty Incubator Binary HTTP codec. Its BinaryHttpParser does not enforce limits on variable-length encoded fields. A remote peer can submit oversized or malformed variable-length field encodings that cause unbounded buffering, resulting in excessive memory consumption and potentially exhausting the process heap.
CVE-2026-61827First seen Aug 21, 2026
CVE-2026-63202 is an unauthenticated denial-of-service vulnerability in the Binary HTTP and Oblivious HTTP codec components of Netty Incubator. Malformed field-section input can cause the BinaryHttpParser field-section decoding logic to make no parsing progress while continuing its loop. This permits a crafted Binary HTTP message to pin a Netty event-loop thread in an infinite loop at full CPU utilization. The weakness is associated with CWE-835 (Infinite Loop) and CWE-400 (Uncontrolled Resource Consumption).
CVE-2026-63202First seen Aug 21, 2026
CVE-2026-61799 is an unchecked variable-length integer length-overflow vulnerability in io.netty.incubator:netty-incubator-codec-bhttp prior to 0.0.23.Final. Malformed Binary HTTP input can cause protocol length values to overflow or be incorrectly narrowed during cumulative byte-count and bounds processing. This can result in unchecked array-index exceptions in BinaryHttpParser or BinaryHttpDecoder rather than controlled decoder errors, terminating the affected connection or channel.
CVE-2026-61799First seen Aug 21, 2026
CVE-2026-54162 is an improper neutralization of terminal escape/control sequences vulnerability in Ember versions before 1.4.2. Ember's interactive terminal user interface can render attacker-controlled fields from Caddy access logs without adequately neutralizing terminal control sequences. Crafted HTTP request data recorded by a monitored Caddy instance can therefore be interpreted by the terminal emulator of an operator viewing the interactive TUI.
CVE-2026-54162First seen Aug 21, 2026
CVE-2026-61798 affects the Netty Incubator OHTTP HPKE BoringSSL codec before version 0.0.23.Final. String representations of affected HPKE asymmetric key and key-pair objects can include raw private-key bytes, and HPKE key-initialization error messages can also expose private-key material. Applications, frameworks, telemetry agents, or diagnostics that log these objects or exceptions can persist complete private keys in logs.
CVE-2026-61798First seen Aug 21, 2026
CVE-2026-35511 is an improper-authentication vulnerability in the Go package github.com/authorizerdev/authorizer's OAuth identity-linking flow. The affected logic can link an OAuth identity to a pre-existing local account based solely on a matching email address without first establishing that the email address on the existing account was verified. This permits an attacker to establish an unverified password-based account using a victim's email address and have it linked when the victim subsequently performs a legitimate OAuth login.
CVE-2026-35511First seen Aug 15, 2026
CVE-2023-39906 is a cross-site request forgery vulnerability in the web-based management interface of the RUCKUS ICX product line. The flaw allows a remote attacker to induce a user of the management interface to follow a crafted link, resulting in unintended requests being sent to the affected device in the context of the victim’s authenticated session. The issue affects the administrative web interface and enables request forgery against actions exposed through that interface.
CVE-2023-39906First seen Aug 23, 2026
CVE-2023-39905 is a cross-site request forgery vulnerability affecting the web-based management interface of the RUCKUS ICX product line. The flaw allows a remote attacker to induce a user of the management interface to follow a crafted link, resulting in unintended requests being sent to the affected device in the context of the victim's authenticated browser session. The issue resides in the management interface's handling of state-changing requests without sufficient protection against forged cross-site requests.
CVE-2023-39905First seen Aug 23, 2026
CVE-2023-39904 is a vulnerability in the web-based management interface of the RUCKUS ICX product line. The issue allows a remote attacker to target a user of the administrative interface with a crafted link and trigger web-layer attacks in the context of that interface. Available information indicates the flaw is associated with cross-site scripting and cross-site request forgery conditions in the management UI, enabling attacker-controlled script execution and unauthorized request submission through the victim’s browser session.
CVE-2023-39904First seen Aug 23, 2026
First seen Aug 24, 2026
First seen Aug 24, 2026
First seen Aug 24, 2026
First seen Aug 24, 2026
First seen Aug 24, 2026
First seen Aug 24, 2026
First seen Aug 24, 2026
First seen Aug 24, 2026
First seen Aug 24, 2026
First seen Aug 24, 2026
CVE-2019-4328 is an XML External Entity vulnerability in HCL AppScan Enterprise affecting multiple XML-processing locations. The flaw is triggered when a user opens, imports, or uploads a specially crafted XML file. Improper handling of external entities allows attacker-controlled XML content to cause the application to resolve external entity references and access local resources available to the victim context. As a result, local file contents readable by the victim can be disclosed and transmitted to an attacker-controlled remote system.
CVE-2019-4328First seen Aug 23, 2026
First seen Aug 23, 2026
First seen Aug 23, 2026
CVE-2021-27744 is a cross-site scripting vulnerability in a default portlet in HCL Digital Experience. The issue can be triggered via a crafted URL, indicating insufficient neutralization or encoding of untrusted input before it is reflected or rendered in a browser context. Affected HCL Digital Experience versions include 8.5, 9.0, and 9.5.
CVE-2021-27744First seen Aug 23, 2026