NVD disclosure day

Published threat advisories for August 23, 2026

CVE advisoryCRITICAL

CVE-2026-78183

DBD::Pg Heap Out-of-Bounds Write Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A heap out-of-bounds write exists in the `quote_float` function of the DBD::Pg Perl module, which can be triggered by specially crafted numeric literals. This vulnerability could lead to memory corruption if an application processes untrusted input through the affected method.

CVE advisoryCRITICAL

CVE-2026-8445

justhtml Markdown Conversion Vulnerability Allows Cross-Site Scripting

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability exists in the justhtml library's Markdown conversion function that allows for cross-site scripting. When converting HTML to Markdown, the library fails to properly escape HTML-significant characters, enabling untrusted input to be rendered as raw HTML and bypass sanitizers. This could lead to the execut

CVE advisoryCRITICAL

CVE-2026-7808

justhtml HTML Sanitization Bypass Leading to Cross-Site Scripting

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The justhtml library has critical vulnerabilities that allow dangerous content to bypass HTML sanitization, potentially leading to cross-site scripting. These issues primarily affect advanced or custom configurations rather than default usage. Exploitation requires an attacker to interact with a web application that us

CVE advisoryCRITICAL

CVE-2026-5388

justhtml Security Issues Allow HTML and JavaScript Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

Multiple security vulnerabilities exist in `justhtml` prior to version 1.15.0 related to URL sanitization and HTML processing. If reachable and relevant, these issues could allow an attacker to inject active HTML and JavaScript into applications. This could alter application output or lead to code injection, potentiall

CVE advisoryCRITICAL

CVE-2026-78155

StackGres Operator Privilege Escalation Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A privilege escalation vulnerability in the StackGres operator allows a low-privilege database owner to gain administrator privileges. This could enable unauthorized control over all databases managed by the operator. Readers should confirm if their environment uses StackGres and assess potential exposure.