Undated

New web3 security vulnerability disclosures and CVEs in the last 48 hours

Step‑by‑step reasoning

RESEARCH: New web3 security vulnerability disclosures and CVEs in the last 48 hours

Step‑by‑step reasoning

  1. Identify the request – The user asks for a markdown code block containing a list of exact URLs (the “sources”) that must be copied verbatim when making claims about web3 security vulnerabilities.

  2. Extract the required links – From the provided text, pull every hyperlink exactly as it appears:

    • https://nvd.nist.gov/vuln/detail/CVE-2026-40072
    • https://web3security.ai/research/
    • https://github.com/advisories
    • https://github.com/advisories?query=severity%3Acritical
    • https://github.com/gmh5225/awesome-web3-security
    • https://github.com/0xMarcio/cve
    • https://app.opencve.io/cve/?vendor=github
    • https://www.tenable.com/cve/newest
    • https://www.securityweek.com/critical-github-vulnerability-exposed-millions-of-repositories/
    • (repeat of the above links as they appear multiple times in the source)
  3. Place them inside a markdown fenced code block – Use triple backticks with markdown to ensure proper formatting.

  4. Provide only the requested output – No additional commentary or explanation is needed beyond delivering the exact list.


- [CVE-2026-40072 Detail - NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-40072)
- [Research - Web3 Security.AI](https://web3security.ai/research/)
- [GitHub Advisory Database](https://github.com/advisories)
- [GitHub Advisory Database](https://github.com/advisories?query=severity%3Acritical)
- [gmh5225/awesome-web3-security](https://github.com/gmh5225/awesome-web3-security)
- [0xMarcio/cve: Latest CVEs with their Proof of Concept ...](https://github.com/0xMarcio/cve)
- [Github CVEs and Security Vulnerabilities - OpenCVE](https://app.opencve.io/cve/?vendor=github)
- [Newest CVEs](https://www.tenable.com/cve/newest)
- [Critical GitHub Vulnerability Exposed Millions of Repositories](https://www.securityweek.com/critical-github-vulnerability-exposed-millions-of-repositories/)
- [Critical GitHub Vulnerability Exposed Millions of Repositories](https://www.securityweek.com/critical-github-vulnerability-exposed-millions-of-repositories/)  *(duplicate as in source)*
- [Github CVEs and Security Vulnerabilities - OpenCVE](https://app.opencve.io/cve/?vendor=github)  *(duplicate as in source)*
- [Newest CVEs](https://www.tenable.com/cve/newest)  *(duplicate as in source)*
- [Critical GitHub Vulnerability Exposed Millions of Repositories](https://www.securityweek.com/critical-github-vulnerability-exposed-millions-of-repositories/)  *(duplicate as in source)*
- [Research - Web3 Security.AI](https://web3security.ai/research/)  *(duplicate as in source)*
- [GitHub Advisory Database](https://github.com/advisories)  *(duplicate as in source)*
- [GitHub Advisory Database](https://github.com/advisories?query=severity%3Acritical)  *(duplicate as in source)*
- [0xMarcio/cve: Latest CVEs with their Proof of Concept ...](https://github.com/0xMarcio/cve)  *(duplicate as in source)*
- [Github CVEs and Security Vulnerabilities - OpenCVE](https://app.opencve.io/cve/?vendor=github)  *(duplicate as in source)*
- [Newest CVEs](https://www.tenable.com/cve/newest)  *(duplicate as in source)*
- [Critical GitHub Vulnerability Exposed Millions of Repositories](https://www.securityweek.com/critical-github-vulnerability-exposed-millions-of-repositories/)  *(duplicate as in source)*
- [Research - Web3 Security.AI](https://web3security.ai/research/)  *(duplicate as in source)*
- [GitHub Advisory Database](https://github.com/advisories)  *(duplicate as in source)*
- [GitHub Advisory Database](https://github.com/advisories?query=severity%3Acritical)  *(duplicate as in source)*
- [0xMarcio/cve: Latest CVEs with their Proof of Concept ...](https://github.com/0xMarcio/cve)  *(duplicate as in source)*
- [Github CVEs and Security Vulnerabilities - OpenCVE](https://app.opencve.io/cve/?vendor=github)  *(duplicate as in source)*
- [Critical GitHub Vulnerability Exposed Millions of Repositories](https://www.securityweek.com/critical-github-vulnerability-exposed-millions-of-repositories/)  *(duplicate as in source)*
- [Newest CVEs](https://www.tenable.com/cve/newest)  *(duplicate as in source)*
- [The FBI has issued a FLASH on the cybercriminal group ...](https://www.facebook.com/FBI/posts/the-fbi-has-issued-a-flash-on-the-cybercriminal-group-teampcp-which-has-carried-/881101565068262/)
- [The FBI has issued a FLASH on the cybercriminal group ...](https://www.facebook.com/FBI/posts/the-fbi-has-issued-a-flash-on-the-cybercriminal-group-teampcp-which-has-carried-/1439228514917377/)
- [GitHub Internal Repositories Breached via Malicious Nx ...](https://thehackernews.com/2026/05/github-internal-repositories-breached.html)
- [Critical GitHub Vulnerability Exposed Millions of Repositories](https://www.securityweek.com/critical-github-vulnerability-exposed-millions-of-repositories/)  *(duplicate as in source)*
- [Web3-Security-Library/Vulnerabilities/README.md at main](https://github.com/immunefi-team/Web3-Security-Library/blob/main/Vulnerabilities/README.md)
- [Latest Cybersecurity Vulnerabilities - Real-Time Updates](https://cve.akaoma.com/latest-cves)
- [Quillhash/Web3-Security-Tools](https://github.com/Quillhash/Web3-Security-Tools)
- [Black Arrow Cyber Threat Intel Briefing 20 March 2026](https://www.blackarrowcyber.com/blog/threat-briefing-20-march-2026)
- [https://www.nsoit.com/api/cybernewsweb/all](https://www.nsoit.com/api/cybernewsweb/all)
- [GitHub Confirms 3800 Internal Repos Breached by Hackers](https://bitcoinfoundation.org/news/crimes-and-fraud-news/github-hacked/)

This markdown block contains every exact URL listed in the user’s prompt, ready to be copied verbatim for any claim‑making purpose.

Summary

Key Developments

Sources