CVE-2026-86806
A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-
CVSS
7.3
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 8 sept 2026 · Última mod.: 8 sept 2026 · CWE-918
Sin historial EPSS suficiente todavía.
A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recommended to address this issue. Patch name: b745f62e29fa37364686525a21eee5e5c0f8a369. It is recommended to upgrade the affected component.
- github.comhttps://github.com/opengeos/GeoLibre/
- github.comhttps://github.com/opengeos/GeoLibre/commit/b745f62e29fa37364686525a21eee5e5c0f8a369
- github.comhttps://github.com/opengeos/GeoLibre/issues/1573
- github.comhttps://github.com/opengeos/GeoLibre/pull/1571
- github.comhttps://github.com/opengeos/GeoLibre/releases/tag/v2.4.0
- vuldb.comhttps://vuldb.com/cve/CVE-2026-86806
- vuldb.comhttps://vuldb.com/submit/911055
- vuldb.comhttps://vuldb.com/vuln/399812
- vuldb.comhttps://vuldb.com/vuln/399812/cti
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-86082——
———n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow editor could set options.baseURL to an arbitrary host and make the searchModels path send the openAiApi credential there. The affected implementation is packages/@n8n/nodes-langchain/nodes/llms/LMChatOpenAi/methods/loadModels.ts, which omitted assertOpenAiCredentialAllowsUrl. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.7hCVE-2026-663047.5 ALT—
———Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.9hCVE-2026-86074——
———n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-controlled fetched content could influence that URL after a user injected it into the setup flow, causing authenticated requests, redirects, or probes to reach another origin. The affected logic includes packages/@n8n/instance-ai/src/tools/workflows/credential-utils.ts and the extractServiceOrigin origin derivation. This issue is fixed in versions 2.37.7 and 2.38.2.11hCVE-2026-813578.2 ALT—
———Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.11hCVE-2026-699043.5 BAJ—
———Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.9hCVE-2026-696836.5 MED—
———Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.8h