Official company update
Technical Analysis: Netty CVE-2026-75595, Next.js CVE-2026-75604, GHSA-2xp9-vwfh-vxw4 & GitPython CVE-2026-78676
OX Security·ox.security·
What the source says
In this blog we’re breaking down each CVE separately, including the root cause, technical overview and patch details. Read our analysis of these 4 critical CVEs Netty CVE-2026-75595 Root Cause A TLS record begins with a 5-byte header, and the handshake message inside it begins with its own 4-byte header: one byte of handshake type, […] The post T
Checking access…
The original publication, including any images and updates, remains with the publisher.
Checking free source access…
More about OX Security
Official · ox.security“Shai-Hulud: Here We Go Again” – “tensorlake” npm Package Hit With MalwareOfficial · ox.securitySSRF in Harbor Webhooks: Any User Can Reach the Server’s Cloud CredentialsOfficial · ox.securityCVE-2026-93355: Account Takeover in LiteLLMOfficial · ox.securityPhantomSub: Malicious npm Campaign Secretly Adds Users to WhatsApp Spam Channels