Miggo Predictive Vulnerability Database
Comprehensive vulnerability intelligence for security teams to gain clarity into CVEs to prioritize and respond with precision.
Concerned about an active attack path? Talk to our security experts and see Miggo in action
Contact UsTop 10 CVEs
New vulnerabilities last 30 days
CVE-2026-22045: Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stall
Traefik ACME TLS-ALPN DoS from unauthenticated attackers stalling TLS handshakes with acme-tls/1 ClientHellos exhausts goroutines and file descriptors.
Analysis:
Available
5.9
medium
1/15/2026
CVE-2025-68671: lakeFS is Missing Timestamp Validation in S3 Gateway Authentication
lakeFS S3 Gateway auth lacks timestamp validation, facilitating replay attacks with captured signed requests for unauthorized access until credential rotation.
Analysis:
Available
6.5
medium
1/15/2026
CVE-2026-1002: Eclipse Vert.x Web static handler file access denial
Vert.x Web static handler cache poisoning DoS via a crafted URI with path traversal sequences denies access to static files by returning an HTTP 404 error.
Analysis:
Available
6.9
medium
1/15/2026
CVE-2026-23622: CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover
easyappointments CSRF bypass in csrf_verify() grants admin takeover via crafted GET requests to state-changing endpoints, creating or modifying admin accounts.
Analysis:
Available
8.7
high
1/15/2026