Coordinated vulnerability disclosures from independent security research. All findings were discovered in isolated lab environments and reported to maintainers prior to publication.
| ID | Product | Affected Versions | Type | CVSS | Status | Advisory |
|---|---|---|---|---|---|---|
| CVE-2026-54155 / GHSA-mq36-523m-x7vv | node-opcua | < 2.166.0 | Authentication Bypass (Missing Nonce Verification) | 8.1 High | Fix merged, CVE Published | Advisory |
| CVE-2026-54156 / GHSA-6wvw-vrw4-363w | node-opcua | < 2.166.0 | Unbounded Nonce Cache Memory Exhaustion DoS | 7.5 High | Fix merged, CVE Published | Advisory |
| CVE-2026-39312 / GHSA-q5g3-qhc6-pr3h | SoftEther VPN | ≤ 5.2.5188 | Pre-Auth DoS (Uncontrolled Memory Allocation) | 7.5 High | Published | Advisory |
| CVE-2026-39886 / GHSA-r3mr-mx8q-jcw5 | OpenEXR | 3.4.0 – 3.4.9 | HTJ2K Signed Integer Overflow (ht_undo_impl() bpl accumulator) |
5.3 Medium | Published | Advisory |
| CVE-2026-20244 | ClamAV | x | ClamAV DMG File Processing Denial of Service Vulnerability | 7.5 High | Published | Advisory |
| CVE-2026-69854 | Azure Spring Cloud | x | Spring Cloud Azure Elevation of Privilege Vulnerability | 9.0 Critical | Published | Advisory |
Research conducted under RA 10175 compliance. All testing performed in isolated Docker/VM lab environments. No live systems were accessed.