<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/januscape-linux-kvm-vulnerability/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T07:42:24.000Z</news:publication_date>
      <news:title>Januscape: A 16-Year-Old Field-Comparison Bug in the Linux KVM Shadow MMU</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/authjs-email-homoglyph-unicode-at-bypass-account-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T14:48:57.279Z</news:publication_date>
      <news:title>Auth.js (@auth/core): Email Magic-Link Homoglyph Bypass Leading to Account Takeover</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/better-auth-pre-account-hijacking-magic-link-email-otp</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T15:51:27.065Z</news:publication_date>
      <news:title>better-auth Pre-Account Hijacking via Magic-Link and Email-OTP Sign-In</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/better-auth-stripe-cross-org-billing-authorization-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:09:36.519Z</news:publication_date>
      <news:title>@better-auth/stripe: Cross-Organization Billing Authorization Bypass</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2024-7708-eclipse-jetty-100-continue-buffer-leak-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T23:10:34.755Z</news:publication_date>
      <news:title>CVE-2024-7708: Eclipse Jetty jetty-server Buffer Leak DoS via 100-Continue Requests</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2025-65964-n8n-git-node-hooks-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:24:08.424Z</news:publication_date>
      <news:title>CVE-2025-65964: n8n Git Node Remote Code Execution via core.hooksPath</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-10050-jetty-digest-auth-iso8859-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T23:11:20.401Z</news:publication_date>
      <news:title>CVE-2026-10050: Eclipse Jetty Digest Authentication Bypass via ISO-8859-1 Encoding Collision</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-15074-fastify-static-route-guard-bypass-dot-dot-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:49:43.911Z</news:publication_date>
      <news:title>CVE-2026-15074: @fastify/static Route Guard Bypass via Dot-Dot Path Traversal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-25800-quinn-proto-assembler-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T14:15:06.684Z</news:publication_date>
      <news:title>CVE-2026-25800: quinn-proto Unbounded Stream Reassembly Memory Exhaustion</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-45623-postcss-sourcemappingurl-arbitrary-file-read</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T15:08:12.038Z</news:publication_date>
      <news:title>CVE-2026-45623: PostCSS Arbitrary File Read via sourceMappingURL Path Traversal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47219-find-my-way-http2-prototype-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T19:48:58.909Z</news:publication_date>
      <news:title>CVE-2026-47219: find-my-way Prototype Property Lookup DoS via HTTP/2 Method</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54673-builder-util-runtime-redirect-credential-leak</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T14:11:32.726Z</news:publication_date>
      <news:title>CVE-2026-54673: builder-util-runtime Cross-Origin Redirect Credential Leak</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55575-liquidjs-pop-filter-memorylimit-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T14:10:07.235Z</news:publication_date>
      <news:title>CVE-2026-55575: LiquidJS pop Filter memoryLimit Accounting Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55607-claude-code-git-worktree-sandbox-escape</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T17:05:05.510Z</news:publication_date>
      <news:title>CVE-2026-55607: @anthropic-ai/claude-code Sandbox Escape via Git Worktree Path Confusion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55685-react-router-manifest-dos-route-matching</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T14:09:01.865Z</news:publication_date>
      <news:title>CVE-2026-55685: react-router Unauthenticated DoS via Inefficient Route Matching on Manifest Endpoint</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55831-netty-spdy-settings-unbounded-map-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:29:57.115Z</news:publication_date>
      <news:title>CVE-2026-55831: netty-codec-http SPDY SETTINGS Frame Unbounded Entry Count DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55833-netty-spdy-zlib-decompression-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:29:10.937Z</news:publication_date>
      <news:title>CVE-2026-55833: netty-codec-http SPDY zlib Decompression Bomb (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56745-netty-spdy-bytebuf-reference-leak-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:50:18.138Z</news:publication_date>
      <news:title>CVE-2026-56745: netty-codec-http SpdyHttpDecoder ByteBuf Reference Leak</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56816-netty-codec-http3-reserved-frame-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:49:54.870Z</news:publication_date>
      <news:title>CVE-2026-56816: netty-codec-http3 Memory Exhaustion via Reserved Frame Types</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56817-netty-codec-xml-xxe-xmldecoder</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:49:22.841Z</news:publication_date>
      <news:title>CVE-2026-56817: netty-codec-xml XmlDecoder XML External Entity Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56820-netty-ocsp-certid-replay-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:48:50.974Z</news:publication_date>
      <news:title>CVE-2026-56820: Netty OcspClient OCSP Response Replay Attack</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56821-netty-ocsp-revocation-bypass-stale-response</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:48:09.376Z</news:publication_date>
      <news:title>CVE-2026-56821: netty-handler-ssl-ocsp Stale OCSP Response Accepted as Valid</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56822-netty-ocsp-toctou-race-condition</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:49:29.532Z</news:publication_date>
      <news:title>CVE-2026-56822: netty-handler-ssl-ocsp TOCTOU Race in OcspServerCertificateValidator</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-57516-ray-read-webdataset-pickle-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T15:54:59.540Z</news:publication_date>
      <news:title>CVE-2026-57516: Ray read_webdataset Arbitrary Code Execution via Default Pickle Decoder</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59206-n8n-prototype-pollution-workflow-credentials</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:30:23.208Z</news:publication_date>
      <news:title>CVE-2026-59206: n8n Prototype Pollution via Workflow Credentials</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59207-n8n-agents-mcp-domain-restriction-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:29:40.928Z</news:publication_date>
      <news:title>CVE-2026-59207: n8n AI Agents MCP Connector Allowed HTTP Request Domains Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59208-n8n-cross-issuer-jwt-account-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:29:02.518Z</news:publication_date>
      <news:title>CVE-2026-59208: n8n Cross-Issuer JWT Token Exchange Account Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59209-n8n-credential-header-leak-pagination-expression</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:31:04.835Z</news:publication_date>
      <news:title>CVE-2026-59209: n8n Shared Credential Header Leak via HTTP Request Pagination Expression</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59214-open-webui-pyodide-same-origin-xss-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T17:03:31.287Z</news:publication_date>
      <news:title>CVE-2026-59214: Open WebUI Stored Web-Worker XSS via Pyodide Same-Origin Code Execution</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59216-open-webui-cross-user-socketio-session-hijack-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T17:14:48.818Z</news:publication_date>
      <news:title>CVE-2026-59216: Open WebUI Cross-User Code Execution via Unvalidated Socket.IO session_id</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59219-open-webui-jwt-revocation-bypass-socketio-websocket</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T17:02:15.874Z</news:publication_date>
      <news:title>CVE-2026-59219: Open WebUI Insufficient Session Expiration on Realtime Endpoints</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59714-open-webui-cross-channel-message-overwrite</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T17:09:57.767Z</news:publication_date>
      <news:title>CVE-2026-59714: open-webui Cross-Channel Message Overwrite via Chat Completion API</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59859-kiota-php-code-injection-dollar-interpolation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:03:16.945Z</news:publication_date>
      <news:title>CVE-2026-59859: Microsoft.OpenApi.Kiota PHP Code Generation Literal Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59860-kiota-xml-doccomment-newline-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:11:48.872Z</news:publication_date>
      <news:title>CVE-2026-59860: Microsoft.OpenApi.Kiota XML Doc-Comment Newline Breakout Code Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59862-kiota-python-generator-enum-description-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:04:35.490Z</news:publication_date>
      <news:title>CVE-2026-59862: Microsoft Kiota Python Generator Code Injection via Enum Description</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59863-kiota-workspace-outputpath-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:44:17.915Z</news:publication_date>
      <news:title>CVE-2026-59863: Microsoft Kiota workspace.json Path Traversal to Arbitrary File Write</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59864-kiota-plugin-static-template-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:01:49.195Z</news:publication_date>
      <news:title>CVE-2026-59864: Microsoft.OpenApi.Kiota Path Traversal via x-ai-* OpenAPI Extensions</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59865-kiota-command-injection-dependency-install-command</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:38:12.237Z</news:publication_date>
      <news:title>CVE-2026-59865: Microsoft Kiota Command Injection via x-ms-kiota-info dependencyInstallCommand</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59866-kiota-x-ms-kiota-info-path-traversal-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:43:02.764Z</news:publication_date>
      <news:title>CVE-2026-59866: Microsoft Kiota Arbitrary File Write and Code Injection via x-ms-kiota-info</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59867-kiota-openapi-ref-ssrf-lfi-rfi</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T17:24:09.750Z</news:publication_date>
      <news:title>CVE-2026-59867: Microsoft Kiota SSRF and Local File Inclusion via Unrestricted OpenAPI $ref Resolution</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59901-netty-bzip2decoder-infinite-loop-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:48:52.326Z</news:publication_date>
      <news:title>CVE-2026-59901: Netty Bzip2Decoder Infinite Loop DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59931-phpspreadsheet-webservice-ssrf-redirect-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T15:10:14.158Z</news:publication_date>
      <news:title>CVE-2026-59931: PHPSpreadsheet SSRF Whitelist Bypass via HTTP Redirect in WEBSERVICE()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59932-phpspreadsheet-gnumeric-gzip-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T15:09:39.960Z</news:publication_date>
      <news:title>CVE-2026-59932: PHPSpreadsheet Gnumeric Reader Gzip Bomb (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59933-phpspreadsheet-ole-sector-chain-infinite-loop-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T15:08:55.657Z</news:publication_date>
      <news:title>CVE-2026-59933: PHPSpreadsheet OLE Sector-Chain Infinite Loop (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59935-pypdf-infinite-loop-ascii85-asciihex-inline-image</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T16:48:07.924Z</news:publication_date>
      <news:title>CVE-2026-59935: pypdf Infinite Loop via Unterminated ASCII85/ASCIIHex Inline Image</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59936-pypdf-infinite-loop-inline-image</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-23T16:48:46.288Z</news:publication_date>
      <news:title>CVE-2026-59936: pypdf Infinite Loop via Unterminated Inline Image</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59939-httplib2-decompression-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T15:29:12.786Z</news:publication_date>
      <news:title>CVE-2026-59939: httplib2 Decompression Bomb Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59940-seroval-fromjson-promise-resolver-type-confusion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T17:22:54.461Z</news:publication_date>
      <news:title>CVE-2026-59940: seroval fromJSON() Promise Resolver Type Confusion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64642-nextjs-turbopack-i18n-middleware-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T23:14:59.347Z</news:publication_date>
      <news:title>CVE-2026-64642: Next.js Middleware Bypass via Turbopack Single-Locale i18n</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64645-nextjs-ssrf-rewrite-destination-hostname</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T23:08:15.228Z</news:publication_date>
      <news:title>CVE-2026-64645: Next.js Server-Side Request Forgery via Rewrite Destination Hostname</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65015-n8n-ai-agent-project-viewer-privilege-escalation-run-node-tool</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:10:09.705Z</news:publication_date>
      <news:title>CVE-2026-65015: n8n AI Agent Project Viewer Privilege Escalation via run_node_tool</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65015-n8n-ai-agent-viewer-privilege-escalation-run-node-tool</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:30:14.719Z</news:publication_date>
      <news:title>CVE-2026-65015: n8n AI Agent Project Viewer Privilege Escalation via run_node_tool</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65016-n8n-sso-instance-role-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:25:28.552Z</news:publication_date>
      <news:title>CVE-2026-65016: n8n SSO Instance-Role Provisioning Privilege Escalation to Owner</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65016-n8n-sso-instance-role-privilege-escalation-1</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:50:53.489Z</news:publication_date>
      <news:title>CVE-2026-65016: n8n SSO Instance-Role Provisioning Privilege Escalation to Instance Owner</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65592-n8n-stored-dom-xss-cachedresulturl</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:08:02.792Z</news:publication_date>
      <news:title>CVE-2026-65592: n8n Stored DOM XSS via Resource Locator cachedResultUrl</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65595-n8n-token-exchange-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:11:50.816Z</news:publication_date>
      <news:title>CVE-2026-65595: n8n Token Exchange Privilege Escalation via Full API Scope Assignment</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65597-n8n-dom-xss-iframe-srcdoc-html-preview</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:08:40.606Z</news:publication_date>
      <news:title>CVE-2026-65597: n8n DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65597-n8n-dom-xss-iframe-srcdoc-html-preview-1</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:28:50.866Z</news:publication_date>
      <news:title>CVE-2026-65597: n8n DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65598-n8n-git-clone-toctou-race-condition-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:09:33.937Z</news:publication_date>
      <news:title>CVE-2026-65598: n8n Git Clone Node TOCTOU Race Condition RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65598-n8n-git-clone-toctou-race-condition-rce-1</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:28:16.742Z</news:publication_date>
      <news:title>CVE-2026-65598: n8n Git Clone Node TOCTOU Race Condition RCE</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-clone-template-hook-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T17:16:00.550Z</news:publication_date>
      <news:title>GitPython: OS Command Injection via --template in clone_from</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-config-section-name-injection-sshcommand-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:31:08.721Z</news:publication_date>
      <news:title>GitPython: git-config section-name injection leads to core.sshCommand RCE</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-diffable-diff-argument-injection-file-overwrite</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T17:21:33.200Z</news:publication_date>
      <news:title>GitPython Argument Injection via Diffable.diff Enables Arbitrary File Overwrite</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-kwarg-value-token-smuggling-os-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:50:55.764Z</news:publication_date>
      <news:title>GitPython: OS Command Injection via Single-Character Kwarg Value Token Smuggling</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/js-yaml-exponential-dos-nested-flow-collections</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:57:18.901Z</news:publication_date>
      <news:title>js-yaml: Exponential Parsing DoS via Nested Flow Collections</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/jupyterlab-image-viewer-svg-xss-new-tab</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T23:28:52.421Z</news:publication_date>
      <news:title>JupyterLab Image Viewer Stored XSS via Malicious SVG File</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/kin-openapi-validation-handler-fail-open-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:56:14.289Z</news:publication_date>
      <news:title>kin-openapi: ValidationHandler Fail-Open Authentication Bypass</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/n8n-allowed-http-domains-bypass-ai-llm-nodes</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:08:58.088Z</news:publication_date>
      <news:title>n8n: Bypass Allowed HTTP Request Domains in AI and LLM Nodes</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/n8n-edit-fields-set-node-prototype-pollution-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:14:16.840Z</news:publication_date>
      <news:title>n8n Edit Fields (Set) Node Prototype Pollution Denial of Service</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/n8n-edit-image-format-injection-arbitrary-file-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:14:53.181Z</news:publication_date>
      <news:title>n8n Edit Image Node Format Injection Allows Arbitrary File Write</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/n8n-embed-login-unverified-email-claim-account-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:09:41.701Z</news:publication_date>
      <news:title>n8n: Account Takeover via Unverified Email Claim in Embed Login Token Exchange</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/n8n-git-node-fetch-pull-pushtags-path-traversal-sandbox-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:24:51.510Z</news:publication_date>
      <news:title>n8n Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/n8n-shared-workflow-inline-subworkflow-credential-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:21:27.876Z</news:publication_date>
      <news:title>n8n: Shared-Workflow Editor Credential Bypass via Inline Sub-Workflow JSON</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/netty-codec-xml-xmlframedecoder-cpu-exhaustion-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:55:04.264Z</news:publication_date>
      <news:title>netty-codec-xml XmlFrameDecoder Denial of Service via CPU Exhaustion</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/postcss-sourcemappingurl-path-traversal-map-file-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:28:37.488Z</news:publication_date>
      <news:title>PostCSS Path Traversal via sourceMappingURL Leads to Arbitrary .map File Disclosure</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/prompty-core-nunjucks-ssti-rce-constructor-prototype</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:29:50.037Z</news:publication_date>
      <news:title>@prompty/core Server-Side Template Injection to Remote Code Execution</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/react-router-rsc-csrf-bypass-action-execution</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T17:11:17.727Z</news:publication_date>
      <news:title>react-router RSC Mode CSRF Bypass ()</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/velocityjs-rce-property-read-function-constructor-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-24T16:35:04.341Z</news:publication_date>
      <news:title>Velocityjs Remote Code Execution via Property-Read to Function Constructor</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>