NVD disclosure day

Published threat advisories for July 18, 2026

CVE advisoryCRITICAL

CVE-2026-9323

Urwid Web Display Session ID Predictability and Exposure

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in the Urwid web display backend due to predictable session identifiers generated using a non-cryptographically secure method. An attacker could observe session IDs or list temporary files to obtain them, then read terminal screens, inject keystrokes for code execution, or crash sessions. This im

CVE advisoryCRITICAL

CVE-2026-16117

@fastify/http-proxy URL Encoding Bypass Allows Access to Hidden Endpoints.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in a web proxy component where URL-encoded request prefixes are not rewritten correctly, potentially allowing attackers to bypass access controls and reach hidden internal or administrative endpoints. This issue could expose sensitive upstream services if the affected proxy is reachable.A vulnera

CVE advisoryCRITICAL

CVE-2025-71392

SurrealDB Escape Sequence Privilege Escalation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in SurrealDB allows authenticated users to inject malicious SurrealQL into table and field names during data export. If a higher-privileged user later imports this data, the injected code executes, potentially leading to privilege escalation and full control of the database instance. This also impacts a

CVE advisoryCRITICAL

CVE-2024-58366

SurrealDB Format String Vulnerability Allows Memory Read and Code Execution.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A format string vulnerability in SurrealDB could allow an attacker with scripting privileges to read arbitrary memory or execute code. This occurs when format string sequences are supplied in error inputs, potentially impacting the confidentiality and integrity of the database process. Uncertainty exists regarding the

CVE advisoryCRITICAL

CVE-2026-16158

@fastify/reply-from Cross-Upstream Data Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in @fastify/reply-from allows unintended data access and modification across services by reusing cached URLs. If reachable, an attacker could exploit this to access or alter data not meant for them. This issue is relevant because it impacts the integrity and confidentiality of inter-service data.

CVE advisoryCRITICAL

CVE-2026-15631

@fastify/http-proxy WebSocket Path Traversal Leading to Upstream Endpoint Exposure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in @fastify/http-proxy allows crafted WebSocket requests to bypass configured rewrite prefixes, potentially exposing unintended upstream endpoints. This occurs due to incomplete validation of the resolved WebSocket destination path. Exploitation requires specific client configurations, but it could be r

CVE advisoryCRITICAL

CVE-2026-47865

VMware Avi Load Balancer Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

VMware Avi Load Balancer has an authentication bypass vulnerability. A threat actor with network access could potentially bypass the authentication mechanism to access the Avi Control plane. This could impact service availability and management capabilities.