To quote my Dad, "Goddamnit, somebody voted for him!"
To quote my Dad, "Goddamnit, somebody voted for him!"
82nd Airborne Division to Little Rock, AR to force Democrat Governor Orval Faubus to integrate public schools thisdayofhistory.com/2026/09/23/s...
82nd Airborne Division to Little Rock, AR to force Democrat Governor Orval Faubus to integrate public schools thisdayofhistory.com/2026/09/23/s...
mississippitoday.org/2024/09/24/1...
mississippitoday.org/2024/09/24/1...
Versions of orval earlier than 8.29.0 do not clean the label (operationId) that comes from an OpenAPI description. If someone provides a specially crafted API spec, their JavaScript…
Too many irrelevant or confusing CVEs? Use stackflag.com
#orval #orvallabs #CVE #infosec
Versions of orval earlier than 8.29.0 do not clean the label (operationId) that comes from an OpenAPI description. If someone provides a specially crafted API spec, their JavaScript…
Too many irrelevant or confusing CVEs? Use stackflag.com
#orval #orvallabs #CVE #infosec
The @orval/effect part of orval (versions 8.14.0 to 8.28.1) can execute malicious JavaScript that an attacker embeds in an API description. This happens when the tool turns certain…
Too many irrelevant or confusing CVEs? Use stackflag.com
#orval #orvallabs #CVE #infosec
The @orval/effect part of orval (versions 8.14.0 to 8.28.1) can execute malicious JavaScript that an attacker embeds in an API description. This happens when the tool turns certain…
Too many irrelevant or confusing CVEs? Use stackflag.com
#orval #orvallabs #CVE #infosec
The orval core library (versions before 8.28.0) can be tricked into executing unwanted code when it builds multipart form data. This happens if an attacker places special placeholders…
Too many irrelevant or confusing CVEs? Use stackflag.com
#orval #orvallabs #CVE #infosec
The orval core library (versions before 8.28.0) can be tricked into executing unwanted code when it builds multipart form data. This happens if an attacker places special placeholders…
Too many irrelevant or confusing CVEs? Use stackflag.com
#orval #orvallabs #CVE #infosec
The orval tool that creates code from OpenAPI definitions can insert unescaped text into the Content-Type header. If an attacker supplies a specially crafted API description, the…
Too many irrelevant or confusing CVEs? Use stackflag.com
#orval #orvallabs #CVE #infosec
The orval tool that creates code from OpenAPI definitions can insert unescaped text into the Content-Type header. If an attacker supplies a specially crafted API description, the…
Too many irrelevant or confusing CVEs? Use stackflag.com
#orval #orvallabs #CVE #infosec
Versions of the orval tool released before 8.30.0 can be tricked into executing unwanted commands when it processes certain API specifications. By inserting special characters into…
Too many irrelevant or confusing CVEs? Use stackflag.com
#orval #orvallabs #CVE #infosec
Versions of the orval tool released before 8.30.0 can be tricked into executing unwanted commands when it processes certain API specifications. By inserting special characters into…
Too many irrelevant or confusing CVEs? Use stackflag.com
#orval #orvallabs #CVE #infosec
If you use orval (versions before 8.29.0) to generate TypeScript code from an OpenAPI description, a specially crafted API file can cause the generated code to run unwanted JavaScript…
Too many irrelevant or confusing CVEs? Use stackflag.com
#orval #orvallabs #CVE #infosec
If you use orval (versions before 8.29.0) to generate TypeScript code from an OpenAPI description, a specially crafted API file can cause the generated code to run unwanted JavaScript…
Too many irrelevant or confusing CVEs? Use stackflag.com
#orval #orvallabs #CVE #infosec
CVE-2026-96758: orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property name…
CVSS 9.8
https://beta.vulnsea.com/cve/CVE-2026-96758
#CVE #infosec #cybersecurity #threatintel
CVE-2026-96758: orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property name…
CVSS 9.8
https://beta.vulnsea.com/cve/CVE-2026-96758
#CVE #infosec #cybersecurity #threatintel
Trans people just want to live, just like black kids just wanted to go to school. And Eisenhower said “let’s go.”
Trans people just want to live, just like black kids just wanted to go to school. And Eisenhower said “let’s go.”
CVE-2026-96757: orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code
CVSS 9.8
https://beta.vulnsea.com/cve/CVE-2026-96757
#CVE #infosec #cybersecurity #threatintel
CVE-2026-96757: orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code
CVSS 9.8
https://beta.vulnsea.com/cve/CVE-2026-96757
#CVE #infosec #cybersecurity #threatintel
CVE ID : CVE-2026-96758
Published : Sept. 23, 2026, 5:17 p.m. | 43 minutes ago
Description : orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer ...
CVE ID : CVE-2026-96758
Published : Sept. 23, 2026, 5:17 p.m. | 43 minutes ago
Description : orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer ...
CVE ID : CVE-2026-96759
Published : Sept. 23, 2026, 5:17 p.m. | 43 minutes ago
Description : orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query m...
CVE ID : CVE-2026-96759
Published : Sept. 23, 2026, 5:17 p.m. | 43 minutes ago
Description : orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query m...