NVD disclosure day

Published threat advisories for April 13, 2026

CVE advisoryCRITICAL

CVE-2026-6100

Python Decompressor Reuse Use-After-Free Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A use-after-free vulnerability exists in Python's compression libraries when a decompressor instance is reused after a memory allocation failure, potentially leading to instability or security risks if the system is under memory pressure. This flaw requires a specific usage pattern where decompressor objects are re-use

CVE advisoryCRITICAL

CVE-2026-31414

Linux kernel could allow internal attacker to cause system outages

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a memory flaw in the Linux kernel to crash the system or escalate their privileges to gain full administrative control. This risk to core server stability could lead to severe operational outages and compromise the security of business applications running on affected systems.

CVE advisoryCRITICAL

CVE-2026-5936

Foxit PDF Services API Server-Side Request Forgery Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Foxit PDF Services API allows attackers to craft URLs that trick the server into making requests to arbitrary destinations. This could enable probing of internal network services, accessing cloud metadata, or bypassing access controls, potentially resulting in sensitive data disclosure and further sy