Search CVE reports


Toggle filters

131 – 140 of 36570 results

Status is adjusted based on your filters.


CVE-2026-27572

Medium priority

Not in release

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of the `wasi:http/types.fields` resource is susceptible to panics when too many fields are added to the...

1 affected package

rust-wasmtime

Package 22.04 LTS
rust-wasmtime Not in release
Show less packages

CVE-2026-27204

Medium priority

Not in release

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of WASI host interfaces are susceptible to guest-controlled resource exhaustion on the host. Wasmtime...

1 affected package

rust-wasmtime

Package 22.04 LTS
rust-wasmtime Not in release
Show less packages

CVE-2026-27195

Medium priority

Not in release

Wasmtime is a runtime for WebAssembly. Starting with Wasmtime 39.0.0, the `component-model-async` feature became the default, which brought with it a new implementation of `[Typed]Func::call_async` which made it capable of calling...

1 affected package

rust-wasmtime

Package 22.04 LTS
rust-wasmtime Not in release
Show less packages

CVE-2026-27590

Medium priority

Not in release

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the request path and then uses that byte index to...

1 affected package

caddy

Package 22.04 LTS
caddy Not in release
Show less packages

CVE-2026-27589

Medium priority

Not in release

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`) exposes a state-changing `POST /load` endpoint that replaces the entire running...

1 affected package

caddy

Package 22.04 LTS
caddy Not in release
Show less packages

CVE-2026-27588

Medium priority

Not in release

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured with a large host list (>100 entries) it becomes...

1 affected package

caddy

Package 22.04 LTS
caddy Not in release
Show less packages

CVE-2026-27587

Medium priority

Not in release

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match pattern contains percent-escape sequences (`%xx`)...

1 affected package

caddy

Package 22.04 LTS
caddy Not in release
Show less packages

CVE-2026-27586

Medium priority

Not in release

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA...

1 affected package

caddy

Package 22.04 LTS
caddy Not in release
Show less packages

CVE-2026-27585

Medium priority

Not in release

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It...

1 affected package

caddy

Package 22.04 LTS
caddy Not in release
Show less packages

CVE-2026-27571

Medium priority

Not in release

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. Prior to versions...

1 affected package

nats-server

Package 22.04 LTS
nats-server Not in release
Show less packages