logo

Last Week in AppSec for 29. January 2026

ID: dd0bd64b-79a9-59c0-b0d1-073a92917afd

STIX ID: report--dd0bd64b-79a9-59c0-b0d1-073a92917afd

Feed Name: Checkmarx Zero

Threat Score
68/100

Date Published: 2026-01-29

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

This bulletin highlights three recent vulnerabilities: a remotely triggerable Denial-of-Service in Oracle Java SE/GraalVM that can crash sandboxed client contexts (CVE-2026-21945); a resource-exhaustion DoS affecting React 19.x Server Function endpoints (CVE-2026-23864); and a path-traversal/Zip Slip in pnpm prior to 10.28.1 allowing attackers to write files arbitrarily—potentially enabling configuration tampering or RCE (CVE-2026-23888). Upgrading the affected packages and applying mitigations such as rate-limiting and monitoring are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.