Search CVE reports


Toggle filters

71 – 80 of 27662 results

Status is adjusted based on your filters.


CVE-2026-44394

Medium priority
Needs evaluation

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via...

1 affected package

keystone

Package 26.04 LTS
keystone Needs evaluation
Show less packages

CVE-2026-43000

Medium priority
Needs evaluation

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted...

1 affected package

keystone

Package 26.04 LTS
keystone Needs evaluation
Show less packages

CVE-2026-42999

Medium priority
Needs evaluation

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary...

1 affected package

keystone

Package 26.04 LTS
keystone Needs evaluation
Show less packages

CVE-2026-42998

Medium priority
Needs evaluation

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the...

1 affected package

keystone

Package 26.04 LTS
keystone Needs evaluation
Show less packages

CVE-2026-45078

Medium priority

Not in release

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied...

1 affected package

matrix-synapse

Package 26.04 LTS
matrix-synapse Not in release
Show less packages

CVE-2026-45076

Medium priority

Not in release

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients....

1 affected package

matrix-synapse

Package 26.04 LTS
matrix-synapse Not in release
Show less packages

CVE-2026-44466

Medium priority
Needs evaluation

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execution of arbitrary commands nested inside an allowlisted command like echo. This...

1 affected package

zed

Package 26.04 LTS
zed Needs evaluation
Show less packages

CVE-2026-44465

Medium priority
Needs evaluation

Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the core.fsmonitor Git configuration option. This allows an attacker to achieve Remote...

1 affected package

zed

Package 26.04 LTS
zed Needs evaluation
Show less packages

CVE-2026-44463

Medium priority
Needs evaluation

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g., PAGER) to execute arbitrary...

1 affected package

zed

Package 26.04 LTS
zed Needs evaluation
Show less packages

CVE-2026-44462

Medium priority
Needs evaluation

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansion chaining (${var@P}), allowing arbitrary command execution under an allowlisted command prefix. This...

1 affected package

zed

Package 26.04 LTS
zed Needs evaluation
Show less packages