SecurityHorrors

Stories you never want to feel on your own skin

22 May 2026

Chromium: The Tab That Never Really Closed

TLDR and details on a Chromium vulnerability allowing attackers to run JavaScript in the background even after the browser is closed.

22 May 2026

BIND 9: Three Cracks in the Resolver Wall

TLDR and affected version summary for three BIND 9 DNS resolver vulnerabilities causing denial of service via high CPU usage.

22 May 2026

Drupal: The Postgres Backdoor Query

TLDR and affected version summary for CVE-2026-9082, a SQL injection vulnerability in Drupal affecting PostgreSQL deployments.

20 May 2026

Composer: Tokens Spilled on the CI Stage

TLDR and affected version summary for CVE-2026-45793, a Composer vulnerability that may expose GitHub authentication tokens in CI logs.

20 May 2026

NGINX njs: One Overflow to Crash Them All

TLDR and affected version summary for CVE-2026-8711, a heap buffer overflow in NGINX JavaScript (njs) that can crash workers and may allow RCE.

14 May 2026

PostgreSQL: Eleven Stitches on a Quiet Afternoon

TLDR and affected version summary for the 11 CVEs patched in the May 14, 2026 PostgreSQL release.

13 May 2026

NGINX: Three Cracks in the Proxy Wall

TLDR and affected version summary for NGINX Rift, CVE-2026-42926, and CVE-2026-42946

7 May 2026

React and Next.js: Thirteen Doors Left Open

TLDR and affected version summary for the May 2026 React and Next.js security advisories.

1 May 2026

Bleeding Llama: The Local AI That Remembered Too Much

TLDR and affected version summary for CVE-2026-7482, the Bleeding Llama vulnerability in Ollama.