Search CVE reports


Toggle filters

931 – 940 of 57429 results

Status is adjusted based on your filters.


CVE-2026-56855

Medium priority
Needs evaluation

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then,...

10 affected packages

golang-1.17, golang-1.20, golang-1.21, golang-1.22, golang-1.23...

Package 16.04 LTS
golang-1.17
golang-1.20
golang-1.21
golang-1.22
golang-1.23
golang-1.24
golang-1.25
golang-1.26
golang-1.27
golang-defaults Needs evaluation
Show all 10 packages Show less packages

CVE-2026-55951

Medium priority
Needs evaluation

The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header...

1 affected package

erlang

Package 16.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-53683

Medium priority
Needs evaluation

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is...

1 affected package

freeipa

Package 16.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-53682

Medium priority
Needs evaluation

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology...

1 affected package

dogtag-pki

Package 16.04 LTS
dogtag-pki Needs evaluation
Show less packages

CVE-2026-17615

Medium priority
Needs evaluation

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration...

2 affected packages

resteasy, resteasy3.0

Package 16.04 LTS
resteasy Needs evaluation
resteasy3.0
Show less packages

CVE-2026-84372

Medium priority
Needs evaluation

(Predis is a flexible and feature-complete Redis and Valkey client for ...)

1 affected package

php-nrk-predis

Package 16.04 LTS
php-nrk-predis Needs evaluation
Show less packages

CVE-2026-84366

Medium priority
Needs evaluation

(Scrapy is a high-level web crawling and scraping framework for Python. ...)

11 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Needs evaluation
python3.4
python3.5 Needs evaluation
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.14
Show all 11 packages Show less packages

CVE-2026-84361

Medium priority
Needs evaluation

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and...

1 affected package

composer

Package 16.04 LTS
composer Needs evaluation
Show less packages

CVE-2026-84311

Medium priority
Needs evaluation

(pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)

2 affected packages

pypdf, pypdf2

Package 16.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages

CVE-2026-84310

Medium priority
Needs evaluation

(pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)

2 affected packages

pypdf, pypdf2

Package 16.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages