← Back to the live CVE advisory feed

CVE-2026-90774: rustypaste

Severity
8.7 (HIGH)
Vendor
ORHUN
Affected versions
0 through before 0.18.1
Fixed version
0.18.1
Patch status
Patched
Published
2026-09-13T11:17:02.163
Modified
2026-09-13T11:17:02.163

Why it matters

High-severity vulnerability requiring prioritized review.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Compare installed versions against the affected version range in the advisory.

Technical summary

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 13, 2026 12:00 PM UTC
86 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-90558
sngrep
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-90561
strapi PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-90562
LangBot PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-90647
ASE2000 V2 Communication Test Set
Reporter: CVE
9.1
CRITICAL
VIEW RECORD
CVE-2026-15451
MemberPress Corporate Accounts PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-90537
AVideo
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-90560
zstd-jni
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-90559
snappy-java
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-90668
UnrealIRCd PATCH
Reporter: CVE
8.7
HIGH
VIEW RECORD
CVE-2026-90770
spug
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-90774
rustypaste PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-90768 EXPLOITED
CAPEv2
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-90553
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-90556
freeciv PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-90493
Internet Download Manager
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-90769
open-notebook PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-90772
amundsen-frontend
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-90651
Socket Firewall PATCH
Reporter: CVE
8.1
HIGH
VIEW RECORD
CVE-2026-90678
HAProxy PATCH
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-86406
User Registration & Membership PATCH
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-89080
Really Simple Security PATCH
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-90616
Product identification pending PATCH
Reporter: CVE
7.4
HIGH
VIEW RECORD
CVE-2026-80071
User Registration & Membership PATCH
Reporter: CONTACT
7.2
HIGH
VIEW RECORD
CVE-2026-90555
vLLM PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-90648
wabt
Reporter: CVE
7.1
HIGH
VIEW RECORD
CVE-2026-90767
Froxlor PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-90536
AVideo
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-90538
AVideo
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-90539
AVideo
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-90541
AVideo
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-90543
AVideo
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-90547
AVideo
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-90548
AVideo
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-90549
AVideo
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-90550
AVideo
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-90551
AVideo
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-90554
vLLM PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-90557
Product identification pending
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-90494
node-restify
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-90513
api-lambda-send-email-ses
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-10148
Booking for Appointments and Events Calendar – Amelia PATCH
Reporter: SECURITY
6.4
MEDIUM
VIEW RECORD
CVE-2026-90535
Flowise PATCH
Reporter: DISCLOSURE
6.3
MEDIUM
VIEW RECORD
CVE-2026-90771
joi
Reporter: DISCLOSURE
6.3
MEDIUM
VIEW RECORD
CVE-2026-90534
Product identification pending PATCH
Reporter: DISCLOSURE
6.1
MEDIUM
VIEW RECORD
CVE-2026-90533
Product identification pending PATCH
Reporter: DISCLOSURE
6
MEDIUM
VIEW RECORD
CVE-2026-90495
Feng Office
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-90498
vhr
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-90504
WARP-Clash-API
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-90509
orion-visor
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-90510
orion-visor
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-90514
School Registration and Fee System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-90485
Uninstaller
Reporter: CNA
5.4
MEDIUM
VIEW RECORD
CVE-2026-88764
Simple Membership PATCH
Reporter: CONTACT
5.4
MEDIUM
VIEW RECORD
CVE-2026-90540
AVideo
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-90542
AVideo
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-90544
AVideo
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-90545
AVideo
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-90546
AVideo
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-90552
AVideo
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-90486
openstatus
Reporter: CNA
5.3
MEDIUM
VIEW RECORD
CVE-2026-77773
Contact Form to Chat Apps | Click to Chat to Order PATCH
Reporter: CONTACT
5.3
MEDIUM
VIEW RECORD
CVE-2026-88995
Bookit — Booking & Appointment Calendar PATCH
Reporter: CONTACT
5.3
MEDIUM
VIEW RECORD
CVE-2026-80072
User Registration & Membership PATCH
Reporter: CONTACT
4.7
MEDIUM
VIEW RECORD
CVE-2026-90679
Product identification pending
Reporter: CVE
4.3
MEDIUM
VIEW RECORD
CVE-2026-88912
rtMedia for WordPress, BuddyPress and bbPress PATCH
Reporter: CONTACT
4.2
MEDIUM
VIEW RECORD
CVE-2026-86407
User Registration & Membership PATCH
Reporter: CONTACT
3.7
LOW
VIEW RECORD
CVE-2026-79300
sesam PATCH
Reporter: CVE
3.5
LOW
VIEW RECORD
CVE-2026-90773
procs
Reporter: DISCLOSURE
2.4
LOW
VIEW RECORD
CVE-2026-90487
xxl-job
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-90488
xxl-job
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-90490
vhr
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-90491
gsubs
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-90492
web_robot
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-90499
vhr
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-90500
vhr
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-90501
vhr
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-90507
WARP-Clash-API
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-90511
OnlineBooks
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-90489
xxl-job
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-90496
Feng Office
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-90497
Feng Office
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-90502
ServerStatus
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-90503
Ludashi
Reporter: CNA
1.8
LOW
VIEW RECORD
CVE-2026-90508
Ludashi
Reporter: CNA
1.8
LOW
VIEW RECORD
CVE-2026-90505
WARP-Clash-API
Reporter: CNA
1.3
LOW
VIEW RECORD
CVE-2026-90506
WARP-Clash-API
Reporter: CNA
1.3
LOW
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.