<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/black-hat-usa-2026-parties-events-guide/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T18:33:09.000Z</news:publication_date>
      <news:title>Black Hat USA 2026 Parties &amp;#038; Events: The Complete Guide (with DEF CON 34)</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/axios-prototype-pollution-proxy-hijack-interceptor-config</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:50:27.496Z</news:publication_date>
      <news:title>axios Node HTTP Adapter Prototype Pollution Proxy Hijack via Interceptor Config Cloning</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2025-67725-tornado-httpheaders-quadratic-dos-repeated-headers</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T19:08:39.101Z</news:publication_date>
      <news:title>CVE-2025-67725: Tornado HTTPHeaders Quadratic DoS via Repeated Header Coalescing</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2025-67726-tornado-multipart-parseparam-quadratic-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T19:08:00.383Z</news:publication_date>
      <news:title>CVE-2025-67726: Tornado Quadratic DoS via Crafted Multipart Parameters</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-13311-shell-quote-quadratic-dos-parse</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:10:33.827Z</news:publication_date>
      <news:title>CVE-2026-13311: shell-quote Quadratic Complexity DoS in parse()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-13676-fast-uri-idn-host-confusion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:09:32.394Z</news:publication_date>
      <news:title>CVE-2026-13676: fast-uri IDN Host Confusion via Failed Canonicalization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-13760-aws-cdk-lib-nodejs-function-docker-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:08:51.119Z</news:publication_date>
      <news:title>CVE-2026-13760: aws-cdk-lib OS Command Injection via nodeModules Version Strings in Docker Bundling</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-20779-gitea-totp-replay-toctou-basic-auth</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:29:38.732Z</news:publication_date>
      <news:title>CVE-2026-20779: Gitea TOTP Passcode Capture-Replay via Basic-Auth and TOCTOU Race</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-20896-gitea-docker-reverse-proxy-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:10:42.189Z</news:publication_date>
      <news:title>CVE-2026-20896: Gitea Docker Image Authentication Bypass via Spoofed X-WEBAUTH-USER Header</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-24451-gitea-fork-sync-private-repo-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:49:18.756Z</news:publication_date>
      <news:title>CVE-2026-24451: Gitea Fork Sync Information Disclosure via merge-upstream</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-27775-gitea-pre-receive-cached-branch-permission-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:48:41.961Z</news:publication_date>
      <news:title>CVE-2026-27775: Gitea Pre-Receive Hook Authorization Bypass via Cached Branch Permission</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47300-aspnetcore-negotiate-ldap-role-elevation-of-privilege</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T16:29:27.094Z</news:publication_date>
      <news:title>CVE-2026-47300: Microsoft.AspNetCore.Authentication.Negotiate Elevation of Privilege via LDAP Role Retrieval</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47302-encryptedxml-nested-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:49:13.083Z</news:publication_date>
      <news:title>CVE-2026-47302: System.Security.Cryptography.Xml EncryptedXml Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47303-aspnetcore-negotiate-ldap-injection-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T16:30:07.072Z</news:publication_date>
      <news:title>CVE-2026-47303: Microsoft.AspNetCore.Authentication.Negotiate LDAP Injection Elevation of Privilege</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50524-dotnet-tls-handshake-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:10:52.413Z</news:publication_date>
      <news:title>CVE-2026-50524: .NET TLS Handshake Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50525-dotnet-encryptedxml-cipherreference-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:09:01.007Z</news:publication_date>
      <news:title>CVE-2026-50525: System.Security.Cryptography.Xml EncryptedXml Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50526-dotnet-build-containers-symlink-container-tampering</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T16:28:49.178Z</news:publication_date>
      <news:title>CVE-2026-50526: Microsoft.NET.Build.Containers Symlink Following Allows Container Image Tampering</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50527-encryptedxml-cipherreference-stack-overflow-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T16:08:10.076Z</news:publication_date>
      <news:title>CVE-2026-50527: System.Security.Cryptography.Xml EncryptedXml Stack Overflow DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50528-dotnet-sslstream-tls-authorization-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:09:29.070Z</news:publication_date>
      <news:title>CVE-2026-50528: .NET SslStream TLS Authorization Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50648-encryptedxml-nested-dos-resource-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:10:15.322Z</news:publication_date>
      <news:title>CVE-2026-50648: System.Security.Cryptography.Xml EncryptedXml Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50650-wpf-xaml-code-injection-elevation-of-privilege</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T16:08:57.985Z</news:publication_date>
      <news:title>CVE-2026-50650: WPF XAML Code Injection Elevation of Privilege</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53515-better-auth-sso-bola-register-provider</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:08:02.302Z</news:publication_date>
      <news:title>CVE-2026-53515: @better-auth/sso Broken Object-Level Authorization on SSO Provider Registration</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54058-pillow-mcidas-oob-read-mmap-stride</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:48:47.857Z</news:publication_date>
      <news:title>CVE-2026-54058: Pillow Out-of-Bounds Read via Undersized McIdas AREA Row Stride</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54059-pillow-pcffontfile-decompression-bomb-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:51:15.511Z</news:publication_date>
      <news:title>CVE-2026-54059: Pillow PcfFontFile Decompression Bomb Protection Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54060-pillow-fontfile-compile-decompression-bomb-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:30:37.778Z</news:publication_date>
      <news:title>CVE-2026-54060: Pillow FontFile.compile() Decompression Bomb Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54291-pgjdbc-scram-channel-binding-downgrade</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T18:08:08.045Z</news:publication_date>
      <news:title>CVE-2026-54291: PostgreSQL JDBC Driver Silent SCRAM Channel-Binding Downgrade</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54481-gitea-internal-api-insecureskipverify-mitm</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:48:12.789Z</news:publication_date>
      <news:title>CVE-2026-54481: Gitea Internal API Client Skips TLS Verification</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54560-cloudreve-oauth-scope-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:29:48.976Z</news:publication_date>
      <news:title>CVE-2026-54560: Cloudreve OAuth Access Token Scope Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55379-pillow-bdffontfile-decompression-bomb-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:29:50.106Z</news:publication_date>
      <news:title>CVE-2026-55379: Pillow BdfFontFile Decompression Bomb Protection Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55380-pillow-gdimagefile-decompression-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:51:06.544Z</news:publication_date>
      <news:title>CVE-2026-55380: Pillow GdImageFile Decompression Bomb (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55514-vllm-mrope-prompt-embeds-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T19:28:51.145Z</news:publication_date>
      <news:title>CVE-2026-55514: vLLM Denial of Service via Prompt Embeds on M-RoPE Models</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55667-filebrowser-scopedfs-removeall-symlink-deletion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:29:15.182Z</news:publication_date>
      <news:title>CVE-2026-55667: File Browser Out-of-Scope File Deletion via Symlink-Following RemoveAll</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55987-gitea-oauth2-deactivated-account-reactivation-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:08:41.760Z</news:publication_date>
      <news:title>CVE-2026-55987: Gitea OAuth2 Sign-In Reactivates Admin-Deactivated Accounts</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56170-aspnetcore-signalr-stateful-reconnect-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T16:28:07.274Z</news:publication_date>
      <news:title>CVE-2026-56170: ASP.NET Core SignalR Stateful Reconnect Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56654-gitea-access-token-scope-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:28:13.940Z</news:publication_date>
      <news:title>CVE-2026-56654: Gitea Privilege Escalation via Access Token Scope Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56750-gitea-remember-me-token-session-not-invalidated</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:29:45.704Z</news:publication_date>
      <news:title>CVE-2026-56750: Gitea Remember-Me Token Theft Leaves Attacker Session Alive</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56755-gitea-debian-registry-dos-decompression-bomb</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:29:02.143Z</news:publication_date>
      <news:title>CVE-2026-56755: Gitea Debian Package Registry Denial of Service via Decompression Bomb and O(N^2) String Concatenation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-57108-dotnet-runtime-x509-nameinfo-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:49:48.269Z</news:publication_date>
      <news:title>CVE-2026-57108: .NET Runtime X.509 Certificate Parsing Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-57894-gitea-migration-ssrf-git-redirect</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:28:13.710Z</news:publication_date>
      <news:title>CVE-2026-57894: Gitea Repository Migration SSRF via Git HTTP Redirect</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58314-gitea-ssrf-cgnat-openid</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:28:16.410Z</news:publication_date>
      <news:title>CVE-2026-58314: Gitea SSRF via Incomplete IP Classifier and Unguarded OpenID Discovery</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58419-gitea-notification-api-private-metadata-leak</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:30:51.691Z</news:publication_date>
      <news:title>CVE-2026-58419: Gitea Notification API Private Issue Metadata Leak After Access Revocation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58421-gitea-codeowners-redos-regexp2-timeout</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:09:19.373Z</news:publication_date>
      <news:title>CVE-2026-58421: Gitea CODEOWNERS ReDoS via Unbounded regexp2 Match</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58422-gitea-oauth2-callback-disabled-account-reactivation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:30:15.821Z</news:publication_date>
      <news:title>CVE-2026-58422: Gitea OAuth2 Callback Improper Access Control Silently Re-enables Disabled Accounts</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58423-gitea-lfs-ssh-subverb-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:51:15.817Z</news:publication_date>
      <news:title>CVE-2026-58423: Gitea LFS SSH Sub-Verb Authentication Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58424-gitea-actions-fork-pr-approval-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:50:36.511Z</news:publication_date>
      <news:title>CVE-2026-58424: Gitea Actions Fork PR Approval Gate Permanent Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58426-gitea-actions-artifacts-v4-hmac-boundary-collision</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:49:57.167Z</news:publication_date>
      <news:title>CVE-2026-58426: Gitea Actions Artifacts V4 HMAC Signature Ambiguity</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58436-gitea-accept-language-redos-underscore-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:29:04.083Z</news:publication_date>
      <news:title>CVE-2026-58436: Gitea Locale Middleware ReDoS via Accept-Language Underscore Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58437-gitea-repo-visibility-push-options</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:08:02.044Z</news:publication_date>
      <news:title>CVE-2026-58437: Gitea Repository Visibility Manipulation via Git Push Options</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58439-gitea-branch-protection-bypass-pr-retarget-stale-approval</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:30:25.760Z</news:publication_date>
      <news:title>CVE-2026-58439: Gitea Branch Protection Bypass via PR Retargeting</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59197-pillow-rankfilter-integer-overflow-heap-oob-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:48:06.904Z</news:publication_date>
      <news:title>CVE-2026-59197: Pillow Heap Out-of-Bounds Write via Integer Overflow in RankFilter</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59199-pillow-heap-oob-write-paste-crop-integer-overflow</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:30:15.960Z</news:publication_date>
      <news:title>CVE-2026-59199: Pillow Heap Out-of-Bounds Write via Signed Coordinate Overflow</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59200-pillow-pdfparser-decompression-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:29:31.412Z</news:publication_date>
      <news:title>CVE-2026-59200: Pillow PdfParser Decompression Bomb DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59204-pillow-jpeg2000-tiled-decode-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:28:47.936Z</news:publication_date>
      <news:title>CVE-2026-59204: Pillow JPEG2000 Tiled Decode Memory Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59205-pillow-imagecms-heap-oob-write-mode-mismatch</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:28:09.955Z</news:publication_date>
      <news:title>CVE-2026-59205: Pillow Controlled Heap Out-of-Bounds Write in ImageCmsTransform.apply()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59725-engine-io-polling-connection-exhaustion-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:09:58.620Z</news:publication_date>
      <news:title>CVE-2026-59725: engine.io Polling Transport Connection Exhaustion (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59731-astro-middleware-authorization-bypass-decode-iteration</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:08:00.647Z</news:publication_date>
      <news:title>CVE-2026-59731: Astro Middleware Authorization Bypass via URL Decode Iteration Limit</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59869-js-yaml-merge-key-quadratic-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:28:34.464Z</news:publication_date>
      <news:title>CVE-2026-59869: js-yaml Merge-Key Chain Quadratic CPU DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59874-node-tar-infinite-loop-negative-entry-size</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:09:17.085Z</news:publication_date>
      <news:title>CVE-2026-59874: node-tar Infinite Loop via Negative Base-256 Entry Size</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59879-immutable-js-list-integer-overflow-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T18:48:15.021Z</news:publication_date>
      <news:title>CVE-2026-59879: Immutable.js List 32-bit Trie Overflow leading to Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59880-immutable-js-hash-collision-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:10:14.149Z</news:publication_date>
      <news:title>CVE-2026-59880: immutable Hash-Collision Algorithmic Complexity DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59884-pyasn1-ber-long-form-tag-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:30:36.685Z</news:publication_date>
      <news:title>CVE-2026-59884: pyasn1 BER Decoder Denial of Service via Unbounded Long-Form Tag IDs</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59885-pyasn1-oid-quadratic-complexity-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:29:53.692Z</news:publication_date>
      <news:title>CVE-2026-59885: pyasn1 Quadratic Complexity OID Decoding Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59886-pyasn1-real-float-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:28:55.818Z</news:publication_date>
      <news:title>CVE-2026-59886: pyasn1 Uncontrolled Resource Consumption in Real Float Conversion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59892-opentelemetry-propagator-jaeger-dos-malformed-header</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:51:33.782Z</news:publication_date>
      <news:title>CVE-2026-59892: @opentelemetry/propagator-jaeger Denial of Service via Malformed Header</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59922-mistune-quadratic-dos-formatting-plugins</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:49:33.963Z</news:publication_date>
      <news:title>CVE-2026-59922: mistune Quadratic Parsing DoS in Formatting Plugins</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59928-mistune-quadratic-reflink-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:28:01.632Z</news:publication_date>
      <news:title>CVE-2026-59928: mistune Quadratic-Time ReDoS via Reference-Link Definitions</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61666-websocket-driver-ruby-host-header-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T18:48:50.000Z</news:publication_date>
      <news:title>CVE-2026-61666: websocket-driver Denial of Service via Malformed Host Header</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61736-lightrag-cors-wildcard-credentials</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:48:51.361Z</news:publication_date>
      <news:title>CVE-2026-61736: lightrag-hku CORS Wildcard + Credentials Any-Origin Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61740-lightrag-hardcoded-jwt-secret-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T21:48:13.747Z</news:publication_date>
      <news:title>CVE-2026-61740: LightRAG Authentication Bypass via Hardcoded JWT Secret and Guest Token Short-Circuit</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61835-directus-ssrf-0000-bypass-file-import</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:29:17.137Z</news:publication_date>
      <news:title>CVE-2026-61835: Directus SSRF Protection Bypass via 0.0.0.0 in File Import</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62685-filebrowser-username-normalization-home-directory-collision</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T22:28:04.043Z</news:publication_date>
      <news:title>CVE-2026-62685: File Browser Username Normalization Home Directory Collision</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/fast-xml-parser-multiple-doctype-entity-expansion-limit-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:08:12.158Z</news:publication_date>
      <news:title>fast-xml-parser: Repeated DOCTYPE Declarations Reset Entity Expansion Limits</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-3150-clone-joined-short-option-upload-pack-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:48:46.435Z</news:publication_date>
      <news:title>GitPython unsafe clone option gate bypass via joined short options</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-clone-from-env-var-exfiltration-expandvars</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:08:47.049Z</news:publication_date>
      <news:title>GitPython: Environment-Variable Exfiltration via Repo.clone_from() URL</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-command-injection-archive-ls-remote-iter-commits</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:30:42.335Z</news:publication_date>
      <news:title>GitPython Command Injection and Arbitrary File Overwrite via Unguarded Git Options</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-command-injection-upload-pack-prefix-abbreviation-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:48:06.178Z</news:publication_date>
      <news:title>GitPython: OS Command Injection via git long-option prefix abbreviation bypass</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/grpc-go-xds-rbac-auth-bypass-rapid-reset-dos-not-rule-panic</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:09:51.465Z</news:publication_date>
      <news:title>gRPC-Go: xDS RBAC Authorization Bypass, HTTP/2 Rapid Reset DoS, and NOT-Rule Panic</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/jackson-core-async-parser-maxnumberlength-bypass-chunked-digits</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:10:38.998Z</news:publication_date>
      <news:title>jackson-core Async Parser maxNumberLength Bypass via Chunked Digit Accumulation (Incomplete Fix)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/sharp-libvips-gif-tiff-vips-loader-vulnerabilities-cve-2026-33327</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:28:43.732Z</news:publication_date>
      <news:title>sharp: Inherited libvips Vulnerabilities in GIF, TIFF, and VIPS Loaders (CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/svgo-removescripts-xss-bypass-namespace-prefix</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:49:20.577Z</news:publication_date>
      <news:title>svgo removeScripts Plugin XSS Bypass via Namespace Prefix and Case-Insensitive URI</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>