<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/container-vulnerability-scanning/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T10:39:17.000Z</news:publication_date>
      <news:title>Container Vulnerability Scanning: A Practical Guide</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2024-7708-eclipse-jetty-100-continue-buffer-leak-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T23:10:34.755Z</news:publication_date>
      <news:title>CVE-2024-7708: Eclipse Jetty jetty-server Buffer Leak DoS via 100-Continue Requests</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2025-65964-n8n-git-node-hooks-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:24:08.424Z</news:publication_date>
      <news:title>CVE-2025-65964: n8n Git Node Remote Code Execution via core.hooksPath</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-10050-jetty-digest-auth-iso8859-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T23:11:20.401Z</news:publication_date>
      <news:title>CVE-2026-10050: Eclipse Jetty Digest Authentication Bypass via ISO-8859-1 Encoding Collision</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-13676-fast-uri-idn-host-confusion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:09:32.394Z</news:publication_date>
      <news:title>CVE-2026-13676: fast-uri IDN Host Confusion via Failed Canonicalization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-13760-aws-cdk-lib-nodejs-function-docker-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:08:51.119Z</news:publication_date>
      <news:title>CVE-2026-13760: aws-cdk-lib OS Command Injection via nodeModules Version Strings in Docker Bundling</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-20779-gitea-totp-replay-toctou-basic-auth</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:29:38.732Z</news:publication_date>
      <news:title>CVE-2026-20779: Gitea TOTP Passcode Capture-Replay via Basic-Auth and TOCTOU Race</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-20896-gitea-docker-reverse-proxy-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:10:42.189Z</news:publication_date>
      <news:title>CVE-2026-20896: Gitea Docker Image Authentication Bypass via Spoofed X-WEBAUTH-USER Header</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-24451-gitea-fork-sync-private-repo-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:49:18.756Z</news:publication_date>
      <news:title>CVE-2026-24451: Gitea Fork Sync Information Disclosure via merge-upstream</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-27775-gitea-pre-receive-cached-branch-permission-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:48:41.961Z</news:publication_date>
      <news:title>CVE-2026-27775: Gitea Pre-Receive Hook Authorization Bypass via Cached Branch Permission</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47300-aspnetcore-negotiate-ldap-role-elevation-of-privilege</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T16:29:27.094Z</news:publication_date>
      <news:title>CVE-2026-47300: Microsoft.AspNetCore.Authentication.Negotiate Elevation of Privilege via LDAP Role Retrieval</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-47303-aspnetcore-negotiate-ldap-injection-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T16:30:07.072Z</news:publication_date>
      <news:title>CVE-2026-47303: Microsoft.AspNetCore.Authentication.Negotiate LDAP Injection Elevation of Privilege</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50526-dotnet-build-containers-symlink-container-tampering</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T16:28:49.178Z</news:publication_date>
      <news:title>CVE-2026-50526: Microsoft.NET.Build.Containers Symlink Following Allows Container Image Tampering</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50527-encryptedxml-cipherreference-stack-overflow-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T16:08:10.076Z</news:publication_date>
      <news:title>CVE-2026-50527: System.Security.Cryptography.Xml EncryptedXml Stack Overflow DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-50650-wpf-xaml-code-injection-elevation-of-privilege</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T16:08:57.985Z</news:publication_date>
      <news:title>CVE-2026-50650: WPF XAML Code Injection Elevation of Privilege</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54058-pillow-mcidas-oob-read-mmap-stride</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:48:47.857Z</news:publication_date>
      <news:title>CVE-2026-54058: Pillow Out-of-Bounds Read via Undersized McIdas AREA Row Stride</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54291-pgjdbc-scram-channel-binding-downgrade</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T18:08:08.045Z</news:publication_date>
      <news:title>CVE-2026-54291: PostgreSQL JDBC Driver Silent SCRAM Channel-Binding Downgrade</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54481-gitea-internal-api-insecureskipverify-mitm</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:48:12.789Z</news:publication_date>
      <news:title>CVE-2026-54481: Gitea Internal API Client Skips TLS Verification</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55831-netty-spdy-settings-unbounded-map-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:29:57.115Z</news:publication_date>
      <news:title>CVE-2026-55831: netty-codec-http SPDY SETTINGS Frame Unbounded Entry Count DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55833-netty-spdy-zlib-decompression-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:29:10.937Z</news:publication_date>
      <news:title>CVE-2026-55833: netty-codec-http SPDY zlib Decompression Bomb (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55987-gitea-oauth2-deactivated-account-reactivation-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:08:41.760Z</news:publication_date>
      <news:title>CVE-2026-55987: Gitea OAuth2 Sign-In Reactivates Admin-Deactivated Accounts</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56170-aspnetcore-signalr-stateful-reconnect-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T16:28:07.274Z</news:publication_date>
      <news:title>CVE-2026-56170: ASP.NET Core SignalR Stateful Reconnect Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56654-gitea-access-token-scope-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:28:13.940Z</news:publication_date>
      <news:title>CVE-2026-56654: Gitea Privilege Escalation via Access Token Scope Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56745-netty-spdy-bytebuf-reference-leak-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:50:18.138Z</news:publication_date>
      <news:title>CVE-2026-56745: netty-codec-http SpdyHttpDecoder ByteBuf Reference Leak</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56750-gitea-remember-me-token-session-not-invalidated</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:29:45.704Z</news:publication_date>
      <news:title>CVE-2026-56750: Gitea Remember-Me Token Theft Leaves Attacker Session Alive</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56755-gitea-debian-registry-dos-decompression-bomb</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:29:02.143Z</news:publication_date>
      <news:title>CVE-2026-56755: Gitea Debian Package Registry Denial of Service via Decompression Bomb and O(N^2) String Concatenation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56816-netty-codec-http3-reserved-frame-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:49:54.870Z</news:publication_date>
      <news:title>CVE-2026-56816: netty-codec-http3 Memory Exhaustion via Reserved Frame Types</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56817-netty-codec-xml-xxe-xmldecoder</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:49:22.841Z</news:publication_date>
      <news:title>CVE-2026-56817: netty-codec-xml XmlDecoder XML External Entity Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56820-netty-ocsp-certid-replay-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:48:50.974Z</news:publication_date>
      <news:title>CVE-2026-56820: Netty OcspClient OCSP Response Replay Attack</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56821-netty-ocsp-revocation-bypass-stale-response</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T21:48:09.376Z</news:publication_date>
      <news:title>CVE-2026-56821: netty-handler-ssl-ocsp Stale OCSP Response Accepted as Valid</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56822-netty-ocsp-toctou-race-condition</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:49:29.532Z</news:publication_date>
      <news:title>CVE-2026-56822: netty-handler-ssl-ocsp TOCTOU Race in OcspServerCertificateValidator</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-57894-gitea-migration-ssrf-git-redirect</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:28:13.710Z</news:publication_date>
      <news:title>CVE-2026-57894: Gitea Repository Migration SSRF via Git HTTP Redirect</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58314-gitea-ssrf-cgnat-openid</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:28:16.410Z</news:publication_date>
      <news:title>CVE-2026-58314: Gitea SSRF via Incomplete IP Classifier and Unguarded OpenID Discovery</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58419-gitea-notification-api-private-metadata-leak</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:30:51.691Z</news:publication_date>
      <news:title>CVE-2026-58419: Gitea Notification API Private Issue Metadata Leak After Access Revocation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58421-gitea-codeowners-redos-regexp2-timeout</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:09:19.373Z</news:publication_date>
      <news:title>CVE-2026-58421: Gitea CODEOWNERS ReDoS via Unbounded regexp2 Match</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58422-gitea-oauth2-callback-disabled-account-reactivation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:30:15.821Z</news:publication_date>
      <news:title>CVE-2026-58422: Gitea OAuth2 Callback Improper Access Control Silently Re-enables Disabled Accounts</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58423-gitea-lfs-ssh-subverb-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:51:15.817Z</news:publication_date>
      <news:title>CVE-2026-58423: Gitea LFS SSH Sub-Verb Authentication Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58424-gitea-actions-fork-pr-approval-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:50:36.511Z</news:publication_date>
      <news:title>CVE-2026-58424: Gitea Actions Fork PR Approval Gate Permanent Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58426-gitea-actions-artifacts-v4-hmac-boundary-collision</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:49:57.167Z</news:publication_date>
      <news:title>CVE-2026-58426: Gitea Actions Artifacts V4 HMAC Signature Ambiguity</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58436-gitea-accept-language-redos-underscore-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:29:04.083Z</news:publication_date>
      <news:title>CVE-2026-58436: Gitea Locale Middleware ReDoS via Accept-Language Underscore Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58437-gitea-repo-visibility-push-options</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:08:02.044Z</news:publication_date>
      <news:title>CVE-2026-58437: Gitea Repository Visibility Manipulation via Git Push Options</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-58439-gitea-branch-protection-bypass-pr-retarget-stale-approval</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T20:30:25.760Z</news:publication_date>
      <news:title>CVE-2026-58439: Gitea Branch Protection Bypass via PR Retargeting</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59197-pillow-rankfilter-integer-overflow-heap-oob-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:48:06.904Z</news:publication_date>
      <news:title>CVE-2026-59197: Pillow Heap Out-of-Bounds Write via Integer Overflow in RankFilter</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59199-pillow-heap-oob-write-paste-crop-integer-overflow</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:30:15.960Z</news:publication_date>
      <news:title>CVE-2026-59199: Pillow Heap Out-of-Bounds Write via Signed Coordinate Overflow</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59200-pillow-pdfparser-decompression-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:29:31.412Z</news:publication_date>
      <news:title>CVE-2026-59200: Pillow PdfParser Decompression Bomb DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59204-pillow-jpeg2000-tiled-decode-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:28:47.936Z</news:publication_date>
      <news:title>CVE-2026-59204: Pillow JPEG2000 Tiled Decode Memory Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59205-pillow-imagecms-heap-oob-write-mode-mismatch</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-20T23:28:09.955Z</news:publication_date>
      <news:title>CVE-2026-59205: Pillow Controlled Heap Out-of-Bounds Write in ImageCmsTransform.apply()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59206-n8n-prototype-pollution-workflow-credentials</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:30:23.208Z</news:publication_date>
      <news:title>CVE-2026-59206: n8n Prototype Pollution via Workflow Credentials</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59207-n8n-agents-mcp-domain-restriction-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:29:40.928Z</news:publication_date>
      <news:title>CVE-2026-59207: n8n AI Agents MCP Connector Allowed HTTP Request Domains Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59208-n8n-cross-issuer-jwt-account-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:29:02.518Z</news:publication_date>
      <news:title>CVE-2026-59208: n8n Cross-Issuer JWT Token Exchange Account Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59209-n8n-credential-header-leak-pagination-expression</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:31:04.835Z</news:publication_date>
      <news:title>CVE-2026-59209: n8n Shared Credential Header Leak via HTTP Request Pagination Expression</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59879-immutable-js-list-integer-overflow-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T18:48:15.021Z</news:publication_date>
      <news:title>CVE-2026-59879: Immutable.js List 32-bit Trie Overflow leading to Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59880-immutable-js-hash-collision-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:10:14.149Z</news:publication_date>
      <news:title>CVE-2026-59880: immutable Hash-Collision Algorithmic Complexity DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59884-pyasn1-ber-long-form-tag-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:30:36.685Z</news:publication_date>
      <news:title>CVE-2026-59884: pyasn1 BER Decoder Denial of Service via Unbounded Long-Form Tag IDs</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59885-pyasn1-oid-quadratic-complexity-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:29:53.692Z</news:publication_date>
      <news:title>CVE-2026-59885: pyasn1 Quadratic Complexity OID Decoding Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59886-pyasn1-real-float-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:28:55.818Z</news:publication_date>
      <news:title>CVE-2026-59886: pyasn1 Uncontrolled Resource Consumption in Real Float Conversion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59892-opentelemetry-propagator-jaeger-dos-malformed-header</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:51:33.782Z</news:publication_date>
      <news:title>CVE-2026-59892: @opentelemetry/propagator-jaeger Denial of Service via Malformed Header</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59901-netty-bzip2decoder-infinite-loop-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:48:52.326Z</news:publication_date>
      <news:title>CVE-2026-59901: Netty Bzip2Decoder Infinite Loop DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61666-websocket-driver-ruby-host-header-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T18:48:50.000Z</news:publication_date>
      <news:title>CVE-2026-61666: websocket-driver Denial of Service via Malformed Host Header</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64642-nextjs-turbopack-i18n-middleware-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T23:14:59.347Z</news:publication_date>
      <news:title>CVE-2026-64642: Next.js Middleware Bypass via Turbopack Single-Locale i18n</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64645-nextjs-ssrf-rewrite-destination-hostname</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T23:08:15.228Z</news:publication_date>
      <news:title>CVE-2026-64645: Next.js Server-Side Request Forgery via Rewrite Destination Hostname</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65015-n8n-ai-agent-project-viewer-privilege-escalation-run-node-tool</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:10:09.705Z</news:publication_date>
      <news:title>CVE-2026-65015: n8n AI Agent Project Viewer Privilege Escalation via run_node_tool</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65015-n8n-ai-agent-viewer-privilege-escalation-run-node-tool</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:30:14.719Z</news:publication_date>
      <news:title>CVE-2026-65015: n8n AI Agent Project Viewer Privilege Escalation via run_node_tool</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65016-n8n-sso-instance-role-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:25:28.552Z</news:publication_date>
      <news:title>CVE-2026-65016: n8n SSO Instance-Role Provisioning Privilege Escalation to Owner</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65016-n8n-sso-instance-role-privilege-escalation-1</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:50:53.489Z</news:publication_date>
      <news:title>CVE-2026-65016: n8n SSO Instance-Role Provisioning Privilege Escalation to Instance Owner</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65592-n8n-stored-dom-xss-cachedresulturl</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:08:02.792Z</news:publication_date>
      <news:title>CVE-2026-65592: n8n Stored DOM XSS via Resource Locator cachedResultUrl</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65595-n8n-token-exchange-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:11:50.816Z</news:publication_date>
      <news:title>CVE-2026-65595: n8n Token Exchange Privilege Escalation via Full API Scope Assignment</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65597-n8n-dom-xss-iframe-srcdoc-html-preview</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:08:40.606Z</news:publication_date>
      <news:title>CVE-2026-65597: n8n DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65597-n8n-dom-xss-iframe-srcdoc-html-preview-1</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:28:50.866Z</news:publication_date>
      <news:title>CVE-2026-65597: n8n DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65598-n8n-git-clone-toctou-race-condition-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:09:33.937Z</news:publication_date>
      <news:title>CVE-2026-65598: n8n Git Clone Node TOCTOU Race Condition RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65598-n8n-git-clone-toctou-race-condition-rce-1</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T18:28:16.742Z</news:publication_date>
      <news:title>CVE-2026-65598: n8n Git Clone Node TOCTOU Race Condition RCE</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/fast-xml-parser-multiple-doctype-entity-expansion-limit-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:08:12.158Z</news:publication_date>
      <news:title>fast-xml-parser: Repeated DOCTYPE Declarations Reset Entity Expansion Limits</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-3150-clone-joined-short-option-upload-pack-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:48:46.435Z</news:publication_date>
      <news:title>GitPython unsafe clone option gate bypass via joined short options</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-clone-from-env-var-exfiltration-expandvars</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:08:47.049Z</news:publication_date>
      <news:title>GitPython: Environment-Variable Exfiltration via Repo.clone_from() URL</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-command-injection-archive-ls-remote-iter-commits</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T21:30:42.335Z</news:publication_date>
      <news:title>GitPython Command Injection and Arbitrary File Overwrite via Unguarded Git Options</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/gitpython-command-injection-upload-pack-prefix-abbreviation-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:48:06.178Z</news:publication_date>
      <news:title>GitPython: OS Command Injection via git long-option prefix abbreviation bypass</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/grpc-go-xds-rbac-auth-bypass-rapid-reset-dos-not-rule-panic</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:09:51.465Z</news:publication_date>
      <news:title>gRPC-Go: xDS RBAC Authorization Bypass, HTTP/2 Rapid Reset DoS, and NOT-Rule Panic</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/jackson-core-async-parser-maxnumberlength-bypass-chunked-digits</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:10:38.998Z</news:publication_date>
      <news:title>jackson-core Async Parser maxNumberLength Bypass via Chunked Digit Accumulation (Incomplete Fix)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/n8n-allowed-http-domains-bypass-ai-llm-nodes</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:08:58.088Z</news:publication_date>
      <news:title>n8n: Bypass Allowed HTTP Request Domains in AI and LLM Nodes</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/n8n-edit-fields-set-node-prototype-pollution-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:14:16.840Z</news:publication_date>
      <news:title>n8n Edit Fields (Set) Node Prototype Pollution Denial of Service</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/n8n-edit-image-format-injection-arbitrary-file-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:14:53.181Z</news:publication_date>
      <news:title>n8n Edit Image Node Format Injection Allows Arbitrary File Write</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/n8n-embed-login-unverified-email-claim-account-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:09:41.701Z</news:publication_date>
      <news:title>n8n: Account Takeover via Unverified Email Claim in Embed Login Token Exchange</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/n8n-git-node-fetch-pull-pushtags-path-traversal-sandbox-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:24:51.510Z</news:publication_date>
      <news:title>n8n Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/n8n-shared-workflow-inline-subworkflow-credential-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-22T22:21:27.876Z</news:publication_date>
      <news:title>n8n: Shared-Workflow Editor Credential Bypass via Inline Sub-Workflow JSON</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/sharp-libvips-gif-tiff-vips-loader-vulnerabilities-cve-2026-33327</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T22:28:43.732Z</news:publication_date>
      <news:title>sharp: Inherited libvips Vulnerabilities in GIF, TIFF, and VIPS Loaders (CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/svgo-removescripts-xss-bypass-namespace-prefix</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-07-21T19:49:20.577Z</news:publication_date>
      <news:title>svgo removeScripts Plugin XSS Bypass via Namespace Prefix and Case-Insensitive URI</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>