Skip to content

Vulnerability scanners flood teams with noise

Security45 posts from 45 people16d active+77 posts in the last 7 days, 5 the 7 days before (steady)

Posts per day

Posts per day45 posts, Aug 27 to Sep 25

The posts behind it

45, newest first
PostDate
Models behaving maliciously only on certain inputs/environments?...on the hardware of pumps in the nuclear power plant in Iran.. Same thing here right?. Is there a way to scan for such patterns in open weight models?. I would guess another solution would be to run two separate models (from different countries ideally) with one cross checking...r/LocalLLaMAu/dowitexSep 24yesterday
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guardlightrag: lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guardAdvisories (advisories.fru.dev)Sep 223 days ago
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attackslightrag: lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force AttacksAdvisories (advisories.fru.dev)Sep 223 days ago
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attackopenbao: OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing AttackAdvisories (advisories.fru.dev)Sep 223 days ago
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Charactersopenbao: OpenBao's Templated Policies Allow Privilege Escalation via Wildcard CharactersAdvisories (advisories.fru.dev)Sep 223 days ago
For engineers working with Terraform/OpenTofu: what parts of the work are still painful?For engineers who work with Terraform/OpenTofu and cloud infrastructure:. I'm curious about the day-to-day parts of the work that tend to be repetitive, manual, frustrating, or easy to get wrong.. Not really looking for opinions about which tools are better. I'm more interested...r/devopsu/MysteriousQuestion99Sep 223 days ago
September update killed functionalityClaude gives false positives and lies about research about 4/5 times (was 1/50 before) ever since the September updateClaude App Store reviewsSep 205 days ago
LMDeploy has an SSRF bypasslmdeploy: LMDeploy has an SSRF bypassAdvisories (advisories.fru.dev)Sep 187 days ago
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loadinglmdeploy: LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loadingAdvisories (advisories.fru.dev)Sep 187 days ago
Jupyter Server: 5xx request logging leaks token-bearing Referer header valuesjupyter: Jupyter Server: 5xx request logging leaks token-bearing Referer header valuesAdvisories (advisories.fru.dev)Sep 178 days ago
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploylmdeploy: LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeployAdvisories (advisories.fru.dev)Sep 169 days ago
vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes withvllm: vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in...Advisories (advisories.fru.dev)Sep 1213 days ago
5 of your servers graded A/B on OpenTrustBench, badges insideHi, I built OpenTrustBench (OSS scanner that grades MCP servers A-F, 8 OWASP-mapped rules, fully local). I scanned the servers repo at d73f99e and yours did well: mcp-fetch: A (90) mcp-sequentialthinking: A (90) mcp-time: B (88) mcp-everything: B (85) mcp-git: B (79) Full...modelcontextprotocol/serversgautamkishoreSep 112 weeks ago
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logoutopen-webui: Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logoutAdvisories (advisories.fru.dev)Sep 102 weeks ago
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLiteopen-webui: Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLiteAdvisories (advisories.fru.dev)Sep 102 weeks ago
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Noden8n: n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model NodeAdvisories (advisories.fru.dev)Sep 102 weeks ago
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-originopen-webui: Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-originAdvisories (advisories.fru.dev)Sep 102 weeks ago
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loaderopen-webui: Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loaderAdvisories (advisories.fru.dev)Sep 102 weeks ago
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletionopen-webui: Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletionAdvisories (advisories.fru.dev)Sep 102 weeks ago
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetchopen-webui: Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetchAdvisories (advisories.fru.dev)Sep 102 weeks ago
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressionsnltk: NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressionsAdvisories (advisories.fru.dev)Sep 82 weeks ago
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressionsnltk: NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressionsAdvisories (advisories.fru.dev)Sep 82 weeks ago
NLTK: Corpus Reader Sandbox Bypassnltk: NLTK: Corpus Reader Sandbox BypassAdvisories (advisories.fru.dev)Sep 82 weeks ago
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcementnltk: NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcementAdvisories (advisories.fru.dev)Sep 82 weeks ago
NLTK: Allowlisted pickle loaders still permit code execution in current sourcenltk: NLTK: Allowlisted pickle loaders still permit code execution in current sourceAdvisories (advisories.fru.dev)Sep 82 weeks ago
NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parsesnltk: NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parsesAdvisories (advisories.fru.dev)Sep 82 weeks ago
NLTK: pathsec SSRF protection can be bypassed when a proxy is configurednltk: NLTK: pathsec SSRF protection can be bypassed when a proxy is configuredAdvisories (advisories.fru.dev)Sep 82 weeks ago
NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Executionnltk: NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code ExecutionAdvisories (advisories.fru.dev)Sep 82 weeks ago
NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)nltk: NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)Advisories (advisories.fru.dev)Sep 82 weeks ago
NLTK: Stable FrameNet and NKJP readers parse outside-root XMLnltk: NLTK: Stable FrameNet and NKJP readers parse outside-root XMLAdvisories (advisories.fru.dev)Sep 82 weeks ago
NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Readnltk: NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File ReadAdvisories (advisories.fru.dev)Sep 82 weeks ago
NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus rootnltk: NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus rootAdvisories (advisories.fru.dev)Sep 82 weeks ago
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL pathsurrealdb: SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL pathAdvisories (advisories.fru.dev)Sep 43 weeks ago
[BUG] Read(**/.env) deny rule prompts on every rg directory search, though rg skips hidden files by default...deny, then ask, then allow, and hook decisions don't bypass permission rules, there is no way to suppress the prompt short of deleting the deny rule. That forces a choice between guarding `.env` and being able to search a repository without a prompt on every call. In unattended...anthropics/claude-codewilliamthorsenSep 33 weeks ago
Subdomain blocked by profanity filter (false positive)Streamlit ForumBenjamin27Sep 23 weeks ago
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling pathsseaweedfs: SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling pathsAdvisories (advisories.fru.dev)Sep 23 weeks ago
NLTK: Default ENFORCE=False Disables All pathsec Security Controlsnltk: NLTK: Default ENFORCE=False Disables All pathsec Security ControlsAdvisories (advisories.fru.dev)Sep 23 weeks ago
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative controlseaweedfs: SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative controlAdvisories (advisories.fru.dev)Sep 23 weeks ago
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed rootsnltk: NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed rootsAdvisories (advisories.fru.dev)Sep 23 weeks ago
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)nltk: NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)Advisories (advisories.fru.dev)Sep 13 weeks ago
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binarynltk: NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binaryAdvisories (advisories.fru.dev)Sep 13 weeks ago
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor , RCE via crafted model artifactmlflow: MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor , RCE via crafted model artifactAdvisories (advisories.fru.dev)Sep 13 weeks ago
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object readseaweedfs: SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object readAdvisories (advisories.fru.dev)Aug 284 weeks ago
Fortigate syslog message parser can be exploited to modify or delete fields from the original messagegraylog2-server: Fortigate syslog message parser can be exploited to modify or delete fields from the original messageAdvisories (advisories.fru.dev)Aug 284 weeks ago
LiteLLM vulnerable to server-side template injection in the /prompts/test endpointlitellm: LiteLLM vulnerable to server-side template injection in the /prompts/test endpointAdvisories (advisories.fru.dev)Aug 274 weeks ago

Companies and products named

Company or productPosts naming it
Claude2
Jupyter1
vLLM1
SQLite1
OpenAI1
n8n1
About this problem

Evidence

45 posts from 45 people in 7 places, about 9 a week over 29 days. Mostly on Advisories (advisories.fru.dev), Claude App Store reviews, Streamlit Forum. Tools named alongside: Claude, Jupyter, vLLM, SQLite.

Frustration Frustration 0 of 3· Seen on fru.dev sites, Reddit, GitHub issues, App Store reviews, Community forums

How it was grouped

Posts that state a pain and match the "vuln-noise" rule. First post Aug 27, 2026, latest Sep 24, 2026. Corroborated: 3 or more posts from 2 or more people or places. Method

History

  • 2026-09-25 Added: Vulnerability scanners flood teams with noise (44 posts)

Rising problems by email

Mondays: the problems in data, tech and AI that grew fastest that week.

Double opt-in. Unsubscribe any time.