<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53728-medplum-external-auth-open-redirect-code-leak</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T13:49:12.059Z</news:publication_date>
      <news:title>CVE-2026-53728: @medplum/core Open Redirect via Prefix-Matched Redirect URI in External Auth Callback</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55158-conflibot-command-injection-branch-name-pull-request-target</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T13:50:52.266Z</news:publication_date>
      <news:title>CVE-2026-55158: conflibot OS Command Injection via Pull Request Branch Name</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64859-new-api-user-list-access-token-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T16:55:04.359Z</news:publication_date>
      <news:title>CVE-2026-64859: new-api User List API Leaks Root Access Token</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64868-new-api-webhook-dos-unbounded-body</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T16:52:06.431Z</news:publication_date>
      <news:title>CVE-2026-64868: new-api Unauthenticated Webhook DoS via Unbounded Body Read</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68518-glances-action-template-sanitizer-bypass-cross-field-command-inje</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T16:49:22.549Z</news:publication_date>
      <news:title>CVE-2026-68518: glances Action-Template Sanitizer Bypass via Cross-Field Shell-Operator Reconstruction</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68519-glances-disable-config-exec-bypass-alert-action-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:30:37.651Z</news:publication_date>
      <news:title>CVE-2026-68519: Glances --disable-config-exec Bypass via On-Alert Action OS Command Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71479-new-api-integer-overflow-quota-billing-self-credit</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T16:50:43.760Z</news:publication_date>
      <news:title>CVE-2026-71479: new-api Integer Overflow in Quota Billing Yields Negative Charges</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71491-sqlparse-quadratic-dos-group-comments</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-17T17:29:06.190Z</news:publication_date>
      <news:title>CVE-2026-71491: sqlparse Quadratic DoS in group_comments</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>