ZÉROJOUR

The zero-day paper — printed from structured content, not scraped prose.
Permanent editionPublic dataset · Sanity GROQGHSA × CISA KEV

Front page — listed in the CISA KEV catalog: treat as actively exploited

Front page · actively exploited

Potential XSS vulnerability in jQuery

CVE-2020-11023 · jquery (npm) · 2020-04-29
6.9 / CVSS 3.x
Fix: upgrade to 3.5.0

No remedy — no published fix; upgrading cannot close these

No remedy

Paramiko rsakey.py allows the SHA-1 algorithm

CVE-2026-44405 · paramiko (pip) · 2026-05-06
3.4 / CVSS 3.x
No fix published

Highest severity — CVSS base score 8.0 and above

Dispatch

Paramiko not properly checking authentication before processing other requests

CVE-2018-7750 · paramiko (pip) · 2018-07-12
9.8 / CVSS 3.x
Fix: upgrade to 2.0.8
Dispatch

Prototype Pollution in minimist

CVE-2021-44906 · minimist (npm) · 2022-03-18
9.8 / CVSS 3.x
Fix: upgrade to 1.2.6
Dispatch

Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

CVE-2026-75604 · next (npm) · 2026-09-08
9 / CVSS 3.x
Fix: upgrade to 15.5.24
Dispatch

Paramiko Authentication Bypass vulnerability

CVE-2018-1000805 · paramiko (pip) · 2018-10-10
8.8 / CVSS 3.x
Fix: upgrade to 2.4.2
Dispatch

node-fetch forwards secure headers to untrusted sites

CVE-2022-0235 · node-fetch (npm) · 2022-01-21
8.8 / CVSS 3.x
Fix: upgrade to 3.1.1
Dispatch

jsonwebtoken unrestricted key type could lead to legacy keys usage

CVE-2022-23539 · jsonwebtoken (npm) · 2022-12-22
8.1 / CVSS 3.x
Fix: upgrade to 9.0.0

Latest dispatches — newest advisories in the dataset

Dispatch

Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

GHSA-2xp9-vwfh-vxw4 · next (npm) · 2026-09-08
0 / CVSS n/a
Fix: upgrade to 15.5.24
Dispatch

Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

CVE-2026-75604 · next (npm) · 2026-09-08
9 / CVSS 3.x
Fix: upgrade to 15.5.24
Dispatch

fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count

CVE-2026-16732 · fastify (npm) · 2026-09-02
6.1 / CVSS 3.x
Fix: upgrade to 5.12.1
Dispatch

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

CVE-2026-18504 · fastify (npm) · 2026-09-02
5.4 / CVSS 3.x
Fix: upgrade to 5.12.1
Dispatch

undici vulnerable to CRLF Injection via blob-like body 'type' property

CVE-2026-15157 · undici (npm) · 2026-08-03
4.2 / CVSS 3.x
Fix: upgrade to 6.28.0
Dispatch

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

CVE-2026-14643 · undici (npm) · 2026-08-03
5.9 / CVSS 3.x
Fix: upgrade to 7.29.0
Dispatch

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

CVE-2026-16729 · undici (npm) · 2026-08-03
4.8 / CVSS 3.x
Fix: upgrade to 6.28.0
Dispatch

undici vulnerable to downstream response desynchronization via retry interceptor

CVE-2026-16728 · undici (npm) · 2026-08-03
4.8 / CVSS 3.x
Fix: upgrade to 6.28.0
Dispatch

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

CVE-2026-13697 · undici (npm) · 2026-08-03
7.4 / CVSS 3.x
Fix: upgrade to 7.29.0
Dispatch

Next.js: Server-Side Request Forgery in Server Actions on custom servers

CVE-2026-64649 · next (npm) · 2026-07-22
0 / CVSS n/a
Fix: upgrade to 15.5.21
Dispatch

Next.js: Cache confusion of response bodies for requests with bodies

CVE-2026-64648 · next (npm) · 2026-07-22
0 / CVSS n/a
Fix: upgrade to 15.5.21
Dispatch

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

CVE-2026-64647 · next (npm) · 2026-07-22
0 / CVSS n/a
Fix: upgrade to 15.5.21

Edition #82 — 16 packages tracked, 1 actively exploited, 1 without a fix. The newsroom →

ZéroJour prints itself from a Sanity dataset of real advisories (GitHub Advisory Database, CC-BY-4.0; CISA KEV). No scraping, no keyword search — headlines are typed fields, scores are numbers, fixes are versions. The newsroom composes, a human approves.