CVE Tools

Four Critical CVEs, the Same Trust Issue

OX SecurityBy Moshe Siman Tov Bustan, Nir Zadok4 min read

Patchnext (npm)sharp (npm)

Our summary

Ongoing security updates have addressed four critical vulnerabilities in widely used infrastructure components, including two distinct issues within the next npm package, one in io.netty:netty-handler, and one in GitPython. These unauthenticated flaws enable severe impacts such as remote code execution via heap overflow in libheif, path traversal on Windows servers exposing encryption keys, mutual TLS (mTLS) bypass, and arbitrary code execution through git hooks.

Developers should immediately upgrade to the fixed releases: update next to version 15.5.24 or 16.3.3, sharp to 0.35.4, libheif to 1.23.2, io.netty:netty-handler to 4.1.137.Final or 4.2.17.Final, and GitPython to 3.1.59. The associated identifiers are CVE-2026-75604, CVE-2026-75595, and CVE-2026-78676.

Read at OX Security

Below is the opening; the full story is at OX Security.

From OX Security

Last week, 4 unauthenticated critical CVEs turned up in 24 hours, all sharing the same mistake: a component trusting the layer next to it

Within a single 24-hour window last week, four critical vulnerabilities landed across widely deployed infrastructure: two in Next.js, one in Netty, one in GitPython. All four are remotely reachable, all four require no authentication, and three of the four sit in code paths that are on by default.…

Continue at OX Security

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store