swagger-typescript-api shipped six advisories today showing a hostile OpenAPI document can inject code into the generated client through path strings, enum values, or the servers[0].url template, exfiltrate auth tokens via a crafted $ref, or reach internal hosts through the same $ref during generation. It's the same bug class that dominated yesterday's watch — datamodel-code-generator's eleven-advisory pile-up — recurring in a different language and ecosystem within twenty-four hours.
Elsewhere, veraPDF logged a five-advisory batch of parser DoS and XXE bugs against malformed PostScript fonts and XFA forms, prebid-server disclosed a CVSS 10 SSRF reachable through any bidder adapter, and Kubernetes Logging operator's Fluentd config-injection bug lets any tenant who can create a Flow resource get remote code execution on the shared log aggregator. CISA also added a hardcoded-password bug in Cisco Secure Firewall Management Center to the KEV catalog, confirmed under active exploitation with an August 1 deadline — the one item today known to be exploited rather than just disclosed; Socket, Phylum, and Aikido otherwise stayed quiet, so this was a disclosure-heavy day, not an active-campaign one.
→ Operational priority for the night patch Cisco Secure FMC before the KEV deadline, then audit any pipeline — TypeScript or Python — that generates code from a spec you don't fully control; that's two proven spec-to-RCE vectors in two days.