NVD disclosure day

Published threat advisories for April 6, 2026

CVE advisoryCRITICAL

CVE-2026-35030

LiteLLM JWT Authentication Cache Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in LiteLLM, an AI gateway, could allow an unauthenticated attacker to impersonate legitimate users by exploiting a JWT authentication cache mechanism. This affects deployments where JWT/OIDC authentication is specifically enabled, potentially leading to unauthorized access to user identities and permiss

CVE advisoryCRITICAL

CVE-2026-34977

Aperi'Solve JPEG Upload Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Aperi'Solve, an open-source steganalysis web platform, allows unauthenticated attackers to achieve root-level command execution in the worker container via a single HTTP request. This could result in unauthorized access and modification of user-uploaded images, analysis results, and password