Search CVE reports


Toggle filters

351 – 360 of 53512 results

Status is adjusted based on your filters.


CVE-2026-102556

Medium priority
Needs evaluation

A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting...

2 affected packages

libsoup2.4, libsoup3

Package 22.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-97711

Medium priority
Needs evaluation

Serialize JavaScript serializes JavaScript values to a superset of JSON that includes regular expressions and functions. From 7.1.1 until 7.1.2, function values serialized by serialize-javascript are not fully protected against...

1 affected package

node-serialize-javascript

Package 22.04 LTS
node-serialize-javascript Needs evaluation
Show less packages

CVE-2026-97689

Medium priority
Needs evaluation

urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field...

2 affected packages

python-urllib3, python-pip

Package 22.04 LTS
python-urllib3 Needs evaluation
python-pip Needs evaluation
Show less packages

CVE-2026-97688

Medium priority
Needs evaluation

urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after...

2 affected packages

python-urllib3, python-pip

Package 22.04 LTS
python-urllib3 Needs evaluation
python-pip Needs evaluation
Show less packages

CVE-2026-97687

Medium priority
Needs evaluation

urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE...

2 affected packages

python-urllib3, python-pip

Package 22.04 LTS
python-urllib3 Needs evaluation
python-pip Needs evaluation
Show less packages

CVE-2026-54873

Low priority
Vulnerable

Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 22.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Vulnerable
edk2 Not affected
edk2-hwe Not in release
Show less packages

CVE-2026-42772

Low priority
Vulnerable

Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 22.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Vulnerable
edk2 Not affected
edk2-hwe Not in release
Show less packages

CVE-2026-102601

Medium priority
Needs evaluation

Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats...

1 affected package

php-league-flysystem

Package 22.04 LTS
php-league-flysystem Needs evaluation
Show less packages

CVE-2026-102598

Medium priority
Needs evaluation

Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first...

1 affected package

python-werkzeug

Package 22.04 LTS
python-werkzeug Needs evaluation
Show less packages

CVE-2026-63209

Medium priority
Needs evaluation

compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with...

1 affected package

golang-github-klauspost-compress

Package 22.04 LTS
golang-github-klauspost-compress Needs evaluation
Show less packages