PatchSiren

Unleash CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Unleash CVE published 2026-08-21

CVE-2026-63466

CVE-2026-63466 is a vulnerability in Unleash, an open-source feature management platform. The issue involves the FeatureEventFormatterMd.format function, which disables Mustache escaping, allowing an editor-level user to inject links into outbound notifications via crafted Slack or Microsoft Teams syntax in usernames. This vulnerability has a CVSS score of 4.1 and is rated MEDIUM. The CVE record was publi [truncated]

HIGH Unleash CVE published 2026-08-21

CVE-2026-63462

The Unleash open-source feature management platform is vulnerable to a denial-of-service attack due to a stack exhaustion issue in the OpenAPI validation error path. An unauthenticated attacker can send a large JSON value to cause a RangeError and terminate the Node process. This issue affects organizations using Unleash, particularly those with untrusted access to the platform. The vulnerability is fixed [truncated]