Known Vulnerabilities for Forge by Digitalbazaar
Listed below are 9 of the newest known vulnerabilities associated with "Forge" by "Digitalbazaar".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49001 json | Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-si... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-48522 json | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.r... | Not Provided | 2026-05-28 | 2026-05-28 |
| CVE-2026-48147 json | Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherRegex() / matches() functions in packages/back... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-45631 json | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET f... | Not Provided | 2026-05-29 | 2026-06-01 |
| CVE-2026-45261 json | GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution v... | Not Provided | 2026-05-28 | 2026-05-30 |
| CVE-2026-44699 json | LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter a... | Not Provided | 2026-05-15 | 2026-05-15 |
| CVE-2026-44351 json | fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in... | Not Provided | 2026-05-13 | 2026-05-14 |
| CVE-2026-44214 json | eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-e... | Not Provided | 2026-05-26 | 2026-05-27 |
| CVE-2026-43968 json | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splitting and... | Not Provided | 2026-05-11 | 2026-05-12 |
| CVE-2026-42869 json | SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCF... | Not Provided | 2026-05-11 | 2026-05-12 |