Vulnerability disclosures
Security research,
responsibly disclosed
Public vulnerabilities discovered by Cantina's autonomous AppSec agents and responsibly disclosed to affected vendors.
How Cantina finds vulnerabilitiesSwipe severity filters · use Product and Sort to narrow results
28 results
Disclosure library
Showing 28 of 28 verified disclosures
Product / ID Finding CVSS Severity Disclosed
3 findings
Adobe Content Credentials CVE-2026-71390 Improper input validation can permit limited unauthorized writes CWE-20 CVSS 4.0 Medium Node.js CVE-2026-58042 Large DNS responses can abort Node.js workers CWE-400 CVSS 5.9 Medium Node.js CVE-2026-58041 Stale SQLite iterators can replay bound writes CWE-367 CVSS 5.3 Medium
1 finding
4 findings
RabbitMQ CVE-2026-57218 OAuth consumers retain access after token expiry CWE-863 CVSS 4.9 Medium RabbitMQ CVE-2026-57217 Topic permissions fail open during metadata errors CWE-755 CVSS 7.0 High RabbitMQ CVE-2026-57216 Proxy handling bypasses loopback-only authentication CWE-290 CVSS 6.8 Medium RabbitMQ CVE-2026-57215 Direct-reply-to bindings enable cross-tenant injection CWE-863 CVSS 7.0 High
3 findings
1 finding
1 finding
2 findings
1 finding
2 findings
2 findings
No disclosures match these filters
Try a broader search or select another severity.
See what Cantina's autonomous AppSec agents find in your environment
Move from exploit path to a human-verified finding your team can act on.