NVD disclosure day

Published threat advisories for January 7, 2026

CVE advisoryCRITICAL

CVE-2025-69264

pnpm Git Dependency Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the pnpm package manager allows git-hosted dependencies to execute arbitrary code during installation, bypassing security protections. This could enable unauthorized code execution on systems using affected versions. Confirmation of pnpm's use in your development or build processes is advised.

CVE advisoryCRITICAL

CVE-2025-12543

Undertow HTTP Request Header Validation Flaw Allows Cache Poisoning and Session Hijacking

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in the Undertow HTTP server core, used in Java applications like WildFly and JBoss EAP, due to improper validation of the Host header in HTTP requests. This flaw allows attackers to send malformed or malicious Host headers, which are processed without rejection, potentially leading to cache poiso

CVE advisoryCRITICAL

CVE-2026-0650

OpenFlagr Authentication Bypass via Path Normalization Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

OpenFlagr has an authentication bypass vulnerability allowing unauthenticated access to protected API endpoints. This could enable unauthorized modification of feature flags or exfiltration of sensitive data. It is uncertain if any systems are affected or what the business impact may be.OpenFlagr, a feature management