Search CVE reports


Toggle filters

381 – 390 of 42041 results

Status is adjusted based on your filters.


CVE-2026-58043

Medium priority
Needs evaluation

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or...

1 affected package

nodejs

Package 24.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-58040

Medium priority
Needs evaluation

An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

1 affected package

nodejs

Package 24.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-56850

Medium priority
Needs evaluation

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability...

1 affected package

nodejs

Package 24.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-56847

Medium priority
Needs evaluation

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under...

1 affected package

nodejs

Package 24.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-16531

Medium priority
Needs evaluation

An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.

1 affected package

pcp

Package 24.04 LTS
pcp Needs evaluation
Show less packages

CVE-2026-16530

Medium priority
Needs evaluation

A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check,...

1 affected package

pcp

Package 24.04 LTS
pcp Needs evaluation
Show less packages

CVE-2026-16529

Medium priority
Needs evaluation

A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service...

1 affected package

pcp

Package 24.04 LTS
pcp Needs evaluation
Show less packages

CVE-2026-16527

Medium priority
Needs evaluation

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

1 affected package

pcp

Package 24.04 LTS
pcp Needs evaluation
Show less packages

CVE-2026-16526

Medium priority
Needs evaluation

A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.

1 affected package

pcp

Package 24.04 LTS
pcp Needs evaluation
Show less packages

CVE-2026-16524

Medium priority
Needs evaluation

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

1 affected package

pcp

Package 24.04 LTS
pcp Needs evaluation
Show less packages