GitLab, Apache RCEs Lead Security Briefing
Critical RCEs in GitLab and Apache HTTP Server, plus SQL injection flaws in Campcodes, dominate today's security news.

GitLab CE/EE is affected by CVE-2021-22205, a critical RCE vulnerability stemming from improper validation of image files parsed by the application. This flaw allows remote attackers to execute arbitrary commands on the server, posing a significant risk to data integrity and system availability. Users are advised to upgrade to a patched version as soon as possible.
Apache HTTP Server versions up to 2.4.48 are vulnerable to CVE-2021-40438, a critical flaw in mod_proxy that enables remote attackers to bypass intended request routing. By crafting a malicious URI, an attacker can force the server to forward requests to an origin server of their choice, potentially leading to unauthorized access or data exfiltration. Prompt patching or upgrading is recommended.
A critical vulnerability, CVE-2017-12615, affects Apache Tomcat versions 7.0.0 through 7.0.79 on Windows when HTTP PUT requests are enabled. Attackers can exploit this by uploading a JSP file to the server via a specially crafted request, leading to remote code execution. This highlights the importance of securing Tomcat configurations and applying updates promptly, especially in environments where file uploads are permitted.
Adobe's BlazeDS 3.2 and earlier, along with several related Oracle and ColdFusion products, are impacted by CVE-2009-3960. This medium-severity vulnerability allows remote attackers to execute unspecified actions, potentially leading to unauthorized access or system compromise. Given its age and the number of affected products, organizations using these legacy systems should prioritize migration or mitigation strategies.
The http-proxy-middleware package is vulnerable to a Denial of Service (DoS) attack via CVE-2024-21536. Versions prior to 2.0.7 and from 3.0.0 before 3.0.3 can be exploited by an unhandled promise rejection error thrown by micromatch, allowing an attacker to crash the Node.js process. This impacts the availability of services relying on this package.
Multiple SQL injection vulnerabilities have been identified in Campcodes Retro Basketball Shoes Online Store 1.0, including CVE-2023-2208, CVE-2023-2207, CVE-2023-2206, CVE-2023-2205, and CVE-2023-2204. These critical flaws affect various files within the application, allowing attackers to manipulate parameters like 'id' and 'email' to inject malicious SQL code, potentially leading to data breaches or complete system compromise.
Oracle PeopleSoft Enterprise CS Campus Community versions 9.0 and 9.2 are affected by several medium-severity vulnerabilities, including CVE-2021-2421, CVE-2017-3577, CVE-2021-35606, and CVE-2020-2912. These flaws, ranging from easily exploitable issues for low-privileged attackers to those requiring higher privileges, can lead to unauthorized access and data manipulation. Patches and security updates should be applied to mitigate these risks.
Sigstore's go library, sigstore-go, has a vulnerability (CVE-2026-54787) prior to version 1.2.1 where it fails to check a bundle signing timestamp against the validity window of an ExpiringKey. This could allow an attacker to bypass signature verification for long-lived signing keys. Users should update to a patched version to ensure the integrity of their signed artifacts.
RubyGems' fast-uri library versions prior to 4.1.2, 3.1.5, and 2.4.4 exhibit a vulnerability (CVE-2026-18446) where it requires a literal double forward slash to recognize a URI authority. This could lead to improper URI parsing when alternative separators are used, potentially causing unexpected behavior or security issues in applications relying on this library for URL handling.
Coturn, an open-source TURN and STUN server implementation, has a vulnerability (CVE-2026-65981) in versions prior to 4.15.0 related to mobility authentication. When using the --mobility flag, the server may authenticate a resumed REFRESH request using the resuming user's credentials without verifying against the original credentials, potentially allowing unauthorized access.
A vulnerability (CVE-2026-62959) in Coturn versions 4.5.2 through 4.14.0 allows an unauthenticated remote client to send a single ordinary TCP packet to trigger an ACME redirect. This occurs when Coturn is configured with --acme-redirect <URL> and exposes a plaintext TCP listener, potentially leading to information disclosure or denial of service.
An unspecified vulnerability exists in CVE-2026-18536 and CVE-2026-63343, with no further details provided in the bundle.
An unspecified vulnerability exists in CVE-2026-18446, with no further details provided in the bundle.