🇳🇴 Join our 1st Vibe Coding Security Wokrshop & Wargame at NDC Oslo

We hunt zero-days so your devs train on them

Every zero-day we find becomes developer security training. Your team trains on SecDim's latest discoveries as soon as we publish them.

Reported Security Advisories

GHSA-w6j9-cwv2-h6wqmedium

Malformed RSA JWK Aborts Parsing of an Entire JWK Set

PythonPyJWT

Sep 8, 2026- CVSS 5.9

A malformed RSA JWK inside a JWK Set aborts parsing of the entire set instead of being skipped, so one bad key can block every valid key in a fetched JWKS from loading.

CVE-2026-27489high

Path traversal via symlink

PythonONNX

Apr 1, 2026- CVSS 8.7

An ineffective symlink check in ONNX's model checker follows a symlink to an arbitrary location, letting a malicious model read files outside the model or user-provided directory. The third recurrence of this vulnerability class, following two earlier incomplete fixes.

CVE-2025-46417high

Exfiltration via DNS linecache and ssl.get_server_certificate

Pythonpicklescan

Oct 24, 2025- CVSS 7.1

A bypass in picklescan, the pickle-file scanner platforms like Hugging Face use to gate malicious ML model uploads, that lets an attacker exfiltrate sensitive data via DNS at model load time even after the file passes scanning.

Give Your Developers the Same Edge

Every disclosure on this page is a new vulnerability in open source code. SecDim turns it into developer security training for your own engineering team.