Search CVE reports


Toggle filters

1001 – 1010 of 43788 results

Status is adjusted based on your filters.


CVE-2026-47191

Medium priority
Needs evaluation

kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit...

1 affected package

kas

Package 24.04 LTS
kas Needs evaluation
Show less packages

CVE-2026-46603

Medium priority
Needs evaluation

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via...

1 affected package

golang-golang-x-image

Package 24.04 LTS
golang-golang-x-image Needs evaluation
Show less packages

CVE-2026-13002

Medium priority
Vulnerable

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution...

1 affected package

dnsmasq

Package 24.04 LTS
dnsmasq Vulnerable
Show less packages

CVE-2026-19879

Medium priority
Needs evaluation

A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes when writing HTTP response...

1 affected package

undertow

Package 24.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-73051

Medium priority

Not in release

actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can...

1 affected package

rust-actix-http

Package 24.04 LTS
rust-actix-http Not in release
Show less packages

CVE-2026-72817

Medium priority
Needs evaluation

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating...

1 affected package

golang-github-go-chi-chi

Package 24.04 LTS
golang-github-go-chi-chi Needs evaluation
Show less packages

CVE-2026-72816

Medium priority
Needs evaluation

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites...

1 affected package

golang-github-go-chi-chi

Package 24.04 LTS
golang-github-go-chi-chi Needs evaluation
Show less packages

CVE-2026-72815

Medium priority
Needs evaluation

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based...

1 affected package

golang-github-go-chi-chi

Package 24.04 LTS
golang-github-go-chi-chi Needs evaluation
Show less packages

CVE-2026-72814

Medium priority

Not in release

The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path;...

1 affected package

rust-actix-files

Package 24.04 LTS
rust-actix-files Not in release
Show less packages

CVE-2026-72813

Medium priority

Not in release

actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a...

1 affected package

rust-actix-files

Package 24.04 LTS
rust-actix-files Not in release
Show less packages