ZÉROJOUR

The zero-day paper — printed from structured content, not scraped prose.
Permanent editionPublic dataset · Sanity GROQGHSA × CISA KEV

The newsroom — the machine composes, only a human advances the workflow

The make-list — pick an advisory, the desk composes it

9.8/10

CVE-2018-7750 — Paramiko not properly checking authentication before processing other requests…

9.8/10

CVE-2021-44906 — Prototype Pollution in minimist…

9/10

CVE-2026-75604 — Next.js: Unauthenticated Remote Code Execution on windows-hosted servers…

8.8/10

CVE-2018-1000805 — Paramiko Authentication Bypass vulnerability…

8.8/10

CVE-2022-0235 — node-fetch forwards secure headers to untrusted sites…

8.1/10

CVE-2022-23539 — jsonwebtoken unrestricted key type could lead to legacy keys usage …

On the press — draft → review → published

published

CVE-2026-4800: lodash vulnerable to Code Injection via `_.template` imports key names

Approved by a human editor — the machine composed, the human signed off

lodash (npm) is affected by CVE-2026-4800. The advisory records a CVSS base score of 8.1/10.

The structured profile reads: reached over network; no special privileges required: none; no user interaction.

Remediation is a version bump: upgrade to 4.18.0.

From the advisory record: Impact The fix for CVE-2021-23337 added validation for the `variable` option in `_.template` but did not apply the same validation to `options.imports` key names. Both paths flow into the same `Function()` constructor sink. When an application passes untrusted input as `options.imports` key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compil…

Published 27/09/2026 08:16:09

draft

CVE-2018-7750: Paramiko not properly checking authentication before processing other requests

Composed by the ZéroJour press desk from structured fields — pending human review

paramiko (pip) is affected by CVE-2018-7750. The advisory records a CVSS base score of 9.8/10.

The structured profile reads: reached over network; no special privileges required: none; no user interaction.

Remediation is a version bump: upgrade to 2.0.8.

From the advisory record: transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

← Front page

ZéroJour prints itself from a Sanity dataset of real advisories (GitHub Advisory Database, CC-BY-4.0; CISA KEV). No scraping, no keyword search — headlines are typed fields, scores are numbers, fixes are versions. The newsroom composes, a human approves.