CVE-2026-35093
published 2026-04-01CVE-2026-35093: A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can…
PriorityP349high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.18%
8.2th percentile
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libinput | < libinput 1.31.1-1 (forky) | libinput 1.31.1-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freedesktop | libinput | < 1.30.3 | 1.30.3 |
| freedesktop | libinput | >= 0 < 1.31.1-1 | 1.31.1-1 |
| freedesktop | libinput | >= 1.30.4 < 1.31.1 | 1.31.1 |
| msrc | azl3_libinput_1.25.0-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libinput_1.21.0-2_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8LOW
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
vendor_msrc·2026-04-02·CVSS 8.8
CVE-2026-35093 [HIGH] CWE-94 Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Red Hat
libinput: libinput: Unauthorized code execution and information disclosure through Lua bytecode plugins
vendor_redhat·2026-04-01·CVSS 8.8
CVE-2026-35093 [HIGH] CWE-94 libinput: libinput: Unauthorized code execution and information disclosure through Lua bytecode plugins
libinput: libinput: Unauthorized code execution and information disclosure through Lua bytecode plugins
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissio
Debian
CVE-2026-35093: libinput - A flaw was found in libinput. A local attacker who can place a specially crafted...
vendor_debian·2026·CVSS 8.8
CVE-2026-35093 [HIGH] CVE-2026-35093: libinput - A flaw was found in libinput. A local attacker who can place a specially crafted...
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.31.1-1)
sid: resolved (fixed in 1.31.1-1)
trixie: resolved
OSV
CVE-2026-35093: (A flaw was found in libinput
osv·2026-04-02·CVSS 8.8
CVE-2026-35093 [HIGH] CVE-2026-35093: (A flaw was found in libinput
(A flaw was found in libinput. A local attacker who can place a special ...)
GHSA
GHSA-mr79-hxw4-8vpf: A flaw was found in libinput
ghsa_unreviewed·2026-04-01
CVE-2026-35093 [HIGH] CWE-94 GHSA-mr79-hxw4-8vpf: A flaw was found in libinput
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.
OSV
CVE-2026-35093: A flaw was found in libinput
osv·2026-04-01·CVSS 8.8
CVE-2026-35093 [HIGH] CVE-2026-35093: A flaw was found in libinput
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0943 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-0943 [HIGH] CVE-2026-0943 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0943 :
Linux Fedora vulnerability analysis and mitigation
HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.
Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
Source : NVD
## 7.5
Score
Published January 19, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 34.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
perl-HarfBuzz-Shaper
perl-HarfBuzz-Shaper-debuginfo
Sources
NVD
## Get a CVE risk assessment
Get a prioritized vi
Wiz
CVE-2026-29022 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-29022 [MEDIUM] CVE-2026-29022 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-29022 :
Linux Fedora vulnerability analysis and mitigation
dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV files. Attackers can exploit a mismatch between sampleLoopCount validation in pass 1 and unconditional processing in pass 2 to overflow heap allocations with 36 bytes of attacker-controlled data through any drwav_init_*_with_metadata() call on untrusted input.
Source : NVD
## 6.8
Score
Published March 3, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Prob
Wiz
CVE-2026-26514 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-26514 [HIGH] CVE-2026-26514 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26514 :
Linux Alpine vulnerability analysis and mitigation
An Argument Injection vulnerability exists in bird-lg-go before commit 6187a4e. The traceroute module uses shlex.Split to parse user input without validation, allowing remote attackers to inject arbitrary flags (e.g., -w, -q) via the q parameter. This can be exploited to cause a Denial of Service (DoS) by exhausting system resources.
Source : NVD
## 7.5
Score
Published March 4, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Alpine
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 38.4
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
bird-lg-go
Sources
NVD
Alpine 3.18, 3.19, 3.20
Wiz
CVE-2026-25554 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.3
CVE-2026-25554 [HIGH] CVE-2026-25554 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25554 :
Linux Fedora vulnerability analysis and mitigation
OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (prior to commit 3822d33) contain a SQL injection vulnerability in the jwt_db_authorize() function in modules/auth_jwt/authorize.c when db_mode is enabled and a SQL database backend is used. The function extracts the tag claim from a JWT without prior signature verification and incorporates the unescaped value directly into a SQL query. An attacker can supply a crafted JWT with a malicious tag claim to manipulate the query result and bypass JWT authentication, allowing impersonation of arbitrary identities.
Source : NVD
## 8.3
Score
Published February 25, 2026
Severity HIGH
CNA Score 8.3
Affected Technologies
Linux Fedora
Has Public Exploit Y
Wiz
CVE-2025-63658 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-63658 [HIGH] CVE-2025-63658 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-63658 :
Linux Alpine vulnerability analysis and mitigation
A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
Source : NVD
## 7.5
Score
Published January 29, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Alpine
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 55.3
Exploitation Probability (EPSS) 0.3
Affected packages and libraries
monkey
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18 Severity HIGH No Fix Added at: Feb 15, 2026
## Get a CVE risk assessment
Get a prioritized vi
Wiz
CVE-2025-63651 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-63651 [HIGH] CVE-2025-63651 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-63651 :
Linux Alpine vulnerability analysis and mitigation
A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
Source : NVD
## 7.5
Score
Published January 29, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Alpine
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 75.7
Exploitation Probability (EPSS) 0.9
Affected packages and libraries
monkey
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18 Severity HIGH No Fix Added at: Feb 20, 2026
## Get a CVE risk assessment
Get a prioritized v
Wiz
CVE-2025-65203 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2025-65203 [HIGH] CVE-2025-65203 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-65203 :
Linux Alpine vulnerability analysis and mitigation
KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowing attacker-controlled script in the sandboxed document to access populated form fields and exfiltrate credentials.
Source : NVD
## 7.1
Score
Published December 17, 2025
Severity HIGH
CNA Score 7.1
Affected Technologies
Linux Alpine
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
keepassxc-browser
Sources
NVD
Alpine 3.23 Severity HIGH No Fix Added at: Jan 28, 2026
Wiz
CVE-2025-63649 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-63649 [HIGH] CVE-2025-63649 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-63649 :
Linux Alpine vulnerability analysis and mitigation
An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted POST request to the server.
Source : NVD
## 7.5
Score
Published January 29, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Alpine
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
monkey
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18 Severity HIGH No Fix Added at: Feb 20, 2026
## Get a CVE risk asses
Wiz
CVE-2025-53470 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.1
CVE-2025-53470 [LOW] CVE-2025-53470 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-53470 :
Linux Alpine vulnerability analysis and mitigation
Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memory read in H4 driver.
This issue affects Apache NimBLE: through 1.8.
This issue requires a broken or bogus Bluetooth controller and thus severity is considered low.
Users are recommended to upgrade to version 1.9, which fixes the issue.
Source : NVD
## 3.1
Score
Published January 10, 2026
Severity LOW
CNA Score 3.1
Affected Technologies
Linux Alpine
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
nimble
Sources
NVD
Alpi
Wiz
CVE-2025-63657 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-63657 [HIGH] CVE-2025-63657 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-63657 :
Linux Alpine vulnerability analysis and mitigation
An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
Source : NVD
## 7.5
Score
Published January 29, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Alpine
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 76.6
Exploitation Probability (EPSS) 1
Affected packages and libraries
monkey
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18 Severity HIGH No Fix Added at: Feb 15, 2026
## Get a CVE risk assessment
Get a prioritized
Wiz
CVE-2025-63655 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-63655 [HIGH] CVE-2025-63655 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-63655 :
Linux Alpine vulnerability analysis and mitigation
A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
Source : NVD
## 7.5
Score
Published January 29, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Alpine
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 76.4
Exploitation Probability (EPSS) 1
Affected packages and libraries
monkey
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18 Severity HIGH No Fix Added at: Feb 15, 2026
## Get a CVE risk assessment
Get a priorit
Wiz
CVE-2026-24480 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-24480 [HIGH] CVE-2026-24480 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24480 :
Linux Fedora vulnerability analysis and mitigation
pull_request_target
pull_request_target
Source : NVD
## 8.7
Score
Published January 27, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 61.8
Exploitation Probability (EPSS) 0.4
Affected packages and libraries
qgis-server
qgis-server-debuginfo
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Fedora vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026
Wiz
CVE-2025-58151 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-58151 [HIGH] CVE-2025-58151 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-58151 :
Linux Alpine vulnerability analysis and mitigation
[varstored: TOCTOU issues with mapped guest memory]
Source : NVD
Published February 5, 2026
CNA Score N/A
Affected Technologies
Linux Alpine
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
xen
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23, edge Has Fix Added at: Jan 28, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Alpine vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published
Wiz
CVE-2026-24044 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.2
CVE-2026-24044 [CRITICAL] CVE-2026-24044 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24044 :
Linux Alpine vulnerability analysis and mitigation
Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing network attackers to potentially recreate the same key pair, allowing them to impersonate the victim server. The secret is generated by the secrets initialization hook, in the ESS Community Helm Chart values, if both initSecrets.enabled is not set to false and synapse.signingKey is not defined. Given a server key in Matrix authenticates both requests originating from and events constructed on a given server, this pote
Wiz
CVE-2025-53477 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-53477 [HIGH] CVE-2025-53477 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-53477 :
Linux Alpine vulnerability analysis and mitigation
NULL Pointer Dereference vulnerability in Apache Nimble.
Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference.
This issue requires disabled asserts and broken or bogus Bluetooth controller and thus severity is considered low.
This issue affects Apache NimBLE: through 1.8.0.
Users are recommended to upgrade to version 1.9.0, which fixes the issue.
Source : NVD
## 7.5
Score
Published January 10, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Alpine
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 58.2
Exploitation Probability (EPSS) 0.4
Affecte
Wiz
CVE-2025-52435 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-52435 [HIGH] CVE-2025-52435 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-52435 :
Linux Alpine vulnerability analysis and mitigation
J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE.
Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to observe the remainder of the exchange.
This issue affects Apache NimBLE: through <= 1.8.0.
Users are recommended to upgrade to version 1.9.0, which fixes the issue.
Source : NVD
## 7.5
Score
Published January 10, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Alpine
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.2
Exploitation Probability (
Wiz
CVE-2026-35093 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-35093 [HIGH] CVE-2026-35093 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-35093 :
Linux Debian vulnerability analysis and mitigation
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.
Source : NVD
## 8.8
Score
Published April 1, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Linux Debian
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4
Exploitat
Wiz
CVE-2025-63650 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-63650 [HIGH] CVE-2025-63650 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-63650 :
Linux Alpine vulnerability analysis and mitigation
An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
Source : NVD
## 7.5
Score
Published January 29, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Alpine
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 76.6
Exploitation Probability (EPSS) 1
Affected packages and libraries
monkey
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18 Severity HIGH No Fix Added at: Feb 20, 2026
## Get a CVE risk assessment
Get a prioritized vie
Wiz
CVE-2026-27734 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-27734 [MEDIUM] CVE-2026-27734 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27734 :
Linux Alpine vulnerability analysis and mitigation
../
Source : NVD
## 6.5
Score
Published February 27, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Linux Alpine
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
github.com/henrygd/beszel
beszel
Sources
NVD
Alpine 3.23 Severity MEDIUM No Fix Added at: Mar 04, 2026
GoLang Severity MEDIUM Has Fix Added at: Mar 02, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Alpine vulnerabilities:
CVE ID
Severity
Score
Te
Wiz
CVE-2025-63652 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-63652 [HIGH] CVE-2025-63652 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-63652 :
Linux Alpine vulnerability analysis and mitigation
A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
Source : NVD
## 7.5
Score
Published January 29, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Alpine
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 76.6
Exploitation Probability (EPSS) 1
Affected packages and libraries
monkey
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18 Severity HIGH No Fix Added at: Feb 15, 2026
## Get a CVE risk assessment
Get a prioritized view
Wiz
CVE-2026-4167 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-4167 [HIGH] CVE-2026-4167 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4167 :
Linux Alpine vulnerability analysis and mitigation
A vulnerability was determined in Belkin F9K1122 1.00.33. This affects the function formReboot of the file /goform/formReboot. This manipulation of the argument webpage causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Source : NVD
## 7.4
Score
Published March 16, 2026
Severity HIGH
CNA Score 7.4
Affected Technologies
Linux Alpine
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 14.9
Exploitation Probability (EPSS) N/A
Affected packages and librari
Wiz
CVE-2025-63653 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-63653 [HIGH] CVE-2025-63653 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-63653 :
Linux Alpine vulnerability analysis and mitigation
An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
Source : NVD
## 7.5
Score
Published January 29, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Alpine
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 76.6
Exploitation Probability (EPSS) 1
Affected packages and libraries
monkey
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18 Severity HIGH No Fix Added at: Feb 15, 2026
## Get a CVE risk assessment
Get a prioritized
Wiz
CVE-2025-62235 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2025-62235 [HIGH] CVE-2025-62235 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-62235 :
Linux Alpine vulnerability analysis and mitigation
Authentication Bypass by Spoofing vulnerability in Apache NimBLE.
Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor.
This issue affects Apache NimBLE: through 1.8.0.
Users are recommended to upgrade to version 1.9.0, which fixes the issue.
Source : NVD
## 8.1
Score
Published January 10, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
Linux Alpine
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
nimble
Sources
NVD
Alpine 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, edge Sever
Wiz
CVE-2025-63656 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-63656 [HIGH] CVE-2025-63656 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-63656 :
Linux Alpine vulnerability analysis and mitigation
An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
Source : NVD
## 7.5
Score
Published January 29, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Alpine
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 76.6
Exploitation Probability (EPSS) 1
Affected packages and libraries
monkey
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18 Severity HIGH No Fix Added at: Feb 15, 2026
## Get a CVE risk assessment
Get a prioritized vi
Wiz
CVE-2025-69217 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2025-69217 [HIGH] CVE-2025-69217 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69217 :
Linux Fedora vulnerability analysis and mitigation
coturn is a free open source implementation of TURN and STUN Server. Versions 4.6.2r5 through 4.7.0-r4 have a bad random number generator for nonces and port randomization after refactoring. Additionally, random numbers aren't generated with openssl's RAND_bytes but libc's random() (if it's not running on Windows). When fetching about 50 sequential nonces (i.e., through sending 50 unauthenticated allocations requests) it is possible to completely reconstruct the current state of the random number generator, thereby predicting the next nonce. This allows authentication while spoofing IPs. An attacker can send authenticated messages without ever receiving the responses, including the nonce (requires knowledge of the cre
Bugzilla
CVE-2026-35093 libinput: libinput: Unauthorized code execution and information disclosure through Lua bytecode plugins
bugzilla·2026-04-01·CVSS 8.8
CVE-2026-35093 [HIGH] CVE-2026-35093 libinput: libinput: Unauthorized code execution and information disclosure through Lua bytecode plugins
CVE-2026-35093 libinput: libinput: Unauthorized code execution and information disclosure through Lua bytecode plugins
An attacker that can deploy a pre-compiled lua bytecode file in {/usr/share,/etc}/libinput/plugins and/or XDG_CONFIG_HOME/libinput/plugins can run unrestricted code in the process that uses libinput, typically the compositor. Lua bytecode is not verified at runtime and the sandboxing restrictions are no longer in effect. This allows an attacker to monitor any keyboard events and send those to an external destination and/or execute virtually any code under the calling process' privileges. For the exploit to work, lua plugins must be enabled in libinput and loaded by the compositor. If libinput is compiled with -Dautoload-plugins any plugin is loaded automatically (Fedora 4
https://access.redhat.com/security/cve/CVE-2026-35093https://bugzilla.redhat.com/show_bug.cgi?id=2453839https://gitlab.freedesktop.org/libinput/libinput/-/work_items/1271https://access.redhat.com/security/cve/CVE-2026-35093https://bugzilla.redhat.com/show_bug.cgi?id=2453839https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35093.json
2026-04-01
Published