Security Digest: January 22, 2026 - 6 Critical Vulnerabilities
Today, six high-severity vulnerabilities pose significant threats across various platforms, including container orchestration systems and Python libraries.
· 4 min read
Today's Critical Security Threats
Executive Summary
Today, six high-severity vulnerabilities pose significant threats across various platforms, including container orchestration systems, Python libraries, and web applications. Immediate patching and configuration updates are imperative to mitigate risks of remote command execution and unauthorized data access.
Critical Vulnerabilities
- CVE-2026-23954: Host Command Execution via Container Image
- Impact: Allows arbitrary command execution on the host system.
- Affected Systems: IncusOS and systems running 'incusd'.
- Immediate Action: Restrict container image uploads and update to latest incusd version.
- Mitigation: Use security patches from the Incus GitHub repository.
- CVE-2026-23953: Newline Injection in YAML Config
- Impact: Enables arbitrary command execution via manipulated configuration files.
- Affected Systems: IncusOS and any system using custom YAML configurations.
- Immediate Action: Validate and sanitize YAML configurations strictly.
- Mitigation: Apply patches from the Incus GitHub repository.
- CVE-2026-24009: PyYAML RCE in docling-core
- Impact: Remote code execution through untrusted YAML deserialization.
- Affected Systems: docling-core versions >=2.21.0, <2.48.4.
- Immediate Action: Upgrade to docling-core 2.48.4 or later.
- Mitigation: Ensure PyYAML version is 5.4 or greater.
- CVE-2026-24006: Stack Overflow via Deep Serialization
- Impact: Causes system crashes via excessive resource consumption.
- Affected Systems: seroval npm package.
- Immediate Action: Set `depthLimit` parameter in serialization methods.
- Mitigation: Update to the latest seroval package version.
- CVE-2025-65098: Credential Theft via Typebot
- Impact: Exfiltrates sensitive credentials via malicious scripts.
- Affected Systems: Applications using @typebot.io/js.
- Immediate Action: Disable script execution on client-side where possible.
- Mitigation: Monitor API access logs for unauthorized credential access.
- CVE-2026-24049: Path Traversal in Wheel Extraction
- Impact: Arbitrary file permission modification through path traversal.
- Affected Systems: wheel and setuptools packages.
- Immediate Action: Update to patched versions of wheel and setuptools.
- Mitigation: Apply vendor-provided patches immediately.
What to Do Now
- Immediately apply available patches for all affected systems.
- Conduct thorough security audits for any systems running vulnerable versions.
- Enhance monitoring for suspicious activities related to these vulnerabilities.
Related Resources
- Vendor advisories and security patches can be found on relevant GitHub repositories.
- Check internal security blog posts for mitigation techniques and updates.