
Report a CVE to HeroDevs
Committed to Security and Confidentiality
At HeroDevs, safeguarding the security of open-source software and its ecosystem is our priority. As a Certified Numbering Authority (CNA), we ensure your vulnerability reports are handled with utmost confidentiality and professionalism.
Report a Vulnerability
When you report a CVE, you can trust that:
- Your submission is reviewed promptly and securely by our team of security experts.
- Details of the vulnerability will not be disclosed until appropriate patches are developed and coordinated with the necessary stakeholders.
- Your role as the reporter will be respected, with attribution provided as per your preference.
Every vulnerability we address strengthens the open-source ecosystem and ensures the continued security of end-of-life software. At HeroDevs, we actively track, assess, and address vulnerabilities to safeguard the security of open source software and protect the businesses that rely on it.
Early Detection and CVE Remediation
187 Security Issues Fixed
(and always looking for more)
Below is a snapshot of the most recent 10 of 75 vulnerabilities in our database, demonstrating our commitment to transparency and proactive security.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Critical
Ingress NGINX
NGINX (ngx_http_proxy_v2_module and ngx_http_grpc_module); reaches Ingress NGINX Controller via the NGINX Open Source build compiled into the controller image
Heap-based Buffer Overflow
NGINX Open Source 1.13.10 through 1.31.1; NGINX Plus R33 through R37.0.1; Ingress NGINX Controller builds that compile against those versions, including upstream v1.15.1
Jul 23, 2026
Critical
Ingress NGINX
NGINX (script engine, map directive); reaches Ingress NGINX Controller via the NGINX Open Source build compiled into the controller image
Heap-based Buffer Overflow
NGINX Open Source 0.9.6 through 1.31.2 (map regex support introduced in 0.9.6, 2011); Ingress NGINX Controller builds that compile against those versions, including upstream v1.15.1
Jul 23, 2026
Medium
Ingress NGINX
NGINX (ngx_http_charset_module); reaches Ingress NGINX Controller via the NGINX Open Source build compiled into the controller image
Buffer Over-read
Information Disclosure
NGINX Open Source 0.3.50 through 1.31.1; Ingress NGINX Controller builds that compile against those versions, including upstream v1.15.1
Jul 23, 2026
High
Jetty
Eclipse Jetty
Authorization Bypass
>=9.4.0 <9.4.63, >=10.0.0 <10.0.31, >=11.0.0 <11.0.31, >=12.0.0 <12.0.36, >=12.1.0 <12.1.10
Jul 16, 2026
Medium
Jetty
Eclipse Jetty
HTTP Request Smuggling
>=9.4.0 <9.4.61, >=10.0.0 <10.0.29, >=11.0.0 <11.0.29, >=12.0.0 <12.0.35, >=12.1.0 <12.1.9
Jul 16, 2026
Low
Apache Tomcat
Apache Tomcat
Authorization Bypass
>=8.5.0 <=8.5.100, >=9.0.0.M1 <9.0.120, >=10.1.0-M1 <10.1.57, >=11.0.0-M1 <11.0.24
Jul 16, 2026
Medium
Node.js
Http Proxy Middleware
Improper Input Validation (4.16)
>=0.16.0 <2.0.10 >=3.0.0 <3.0.6 >=4.0.0 <4.1.0
Jul 14, 2026
High
Protocol Buffers
Protocol Buffers
Denial of Service
<3.25.5, >=4.0.0-RC1 <4.27.5, >=4.28.0-RC1 <4.28.2
Jul 9, 2026
High
Angular
Angular
Cross-Site Scripting
>= 22.0.0-next.0 < 22.0.1 >= 21.0.0-next.0 < 21.2.17 >= 20.0.0-next.0 < 20.3.25 <= 19.2.25
Jul 9, 2026
For more details on CVEs found in end-of-life software, visit our vulnerability directory.