<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54167-pipelines-as-code-github-app-jwt-exfiltration-enterprise-host-hea</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:31:01.063Z</news:publication_date>
      <news:title>CVE-2026-54167: Pipelines-as-Code GitHub App JWT Exfiltration via Untrusted X-GitHub-Enterprise-Host Header</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54175-backpack-crud-unverified-password-change-mass-assignment</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:28:48.686Z</news:publication_date>
      <news:title>CVE-2026-54175: Laravel Backpack CRUD Unverified Password Change via Mass Assignment</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59989-phalcon-volt-join-filter-code-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:28:49.288Z</news:publication_date>
      <news:title>CVE-2026-59989: Phalcon Volt Compiler join Filter PHP Code Injection (RCE)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61539-xinference-eval-injection-llama3-tool-parser-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:21:36.323Z</news:publication_date>
      <news:title>CVE-2026-61539: Xinference Remote Code Execution via Unsafe eval() in Llama3 Tool-Call Parser</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63135-yourls-stored-xss-referer-statistics-chart</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:14:56.252Z</news:publication_date>
      <news:title>CVE-2026-63135: YOURLS Stored XSS via Crafted Referer Header in Statistics Chart</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63421-keystone-graphql-maxtake-negative-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:30:01.913Z</news:publication_date>
      <news:title>CVE-2026-63421: @keystone-6/core graphql.maxTake Bypass via Negative take</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63462-unleash-server-dos-recursive-json-stringify</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T19:28:56.085Z</news:publication_date>
      <news:title>CVE-2026-63462: unleash-server Unauthenticated DoS via Recursive JSON Serialization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64679-atlantis-workspace-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:24:48.031Z</news:publication_date>
      <news:title>CVE-2026-64679: Atlantis Workspace Path Traversal Allows Out-of-Bounds Directory Operations</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68508-hydra-core-instantiate-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:11:32.435Z</news:publication_date>
      <news:title>CVE-2026-68508: hydra-core Unsafe Instantiation Code Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-76904-geotools-postgis-jsonarraycontains-sql-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T20:29:07.192Z</news:publication_date>
      <news:title>CVE-2026-76904: GeoTools gt-jdbc-postgis Unauthenticated SQL Injection via jsonArrayContains</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-76905-kin-openapi-multipart-nil-pointer-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:23:42.998Z</news:publication_date>
      <news:title>CVE-2026-76905: kin-openapi openapi3filter Nil-Pointer Panic via Malformed multipart/form-data</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-77354-kin-openapi-deepobject-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:17:17.937Z</news:publication_date>
      <news:title>CVE-2026-77354: kin-openapi Uncontrolled Memory Allocation via deepObject Query Parameter</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-77413-jsonata-arbitrary-code-execution-prototype-lookup</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:15:58.897Z</news:publication_date>
      <news:title>CVE-2026-77413: jsonata Arbitrary Code Execution via Prototype Chain Escape</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-77414-jsonata-code-injection-hasownproperty-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:10:16.473Z</news:publication_date>
      <news:title>CVE-2026-77414: jsonata Arbitrary Code Execution via hasOwnProperty Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-77415-jsonata-code-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:09:07.907Z</news:publication_date>
      <news:title>CVE-2026-77415: jsonata Arbitrary Code Execution via Crafted Expression</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>