PatchSiren

Thinkst Applied Research CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Thinkst Applied Research CVE published 2026-07-22

CVE-2026-16551

A denial-of-service vulnerability exists in Thinkst Applied Research OpenCanary (MongoDB module), allowing for excessive allocation. This issue affects OpenCanary 0.9.8 only. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. The vulnerability is caused by excessive allocation in the MongoDB module of OpenCanary 0.9.8, which can lead to a denial-of-service condition. Users of OpenCanary 0 [truncated]

LOW Thinkst Applied Research CVE published 2026-06-10

CVE-2026-11859

CVE-2026-11859 is an HTML injection vulnerability in the 'fetch links' email sent by Thinkst Applied Research Canarytokens. This issue enables Interface Manipulation and Cross-Site Scripting (XSS) in email clients that render HTML emails. The vulnerability affects Canarytokens from Docker tag sha-c0f3cf142 before sha-08c3f93d and from Git commit c0f3cf142 before 08c3f93d. The CVSS score for this vulnerabi [truncated]