Search CVE reports


Toggle filters

401 – 410 of 36697 results

Status is adjusted based on your filters.


CVE-2026-26996

Medium priority
Needs evaluation

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many...

1 affected package

node-minimatch

Package 22.04 LTS
node-minimatch Needs evaluation
Show less packages

CVE-2026-26994

Medium priority
Needs evaluation

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. In versions 1.6.7 and below, uTLS did not implement the TLS 1.3 downgrade protection mechanism...

1 affected package

golang-refraction-networking-utls

Package 22.04 LTS
golang-refraction-networking-utls Needs evaluation
Show less packages

CVE-2026-26960

Medium priority
Needs evaluation

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction...

1 affected package

node-tar

Package 22.04 LTS
node-tar Needs evaluation
Show less packages

CVE-2026-26065

Medium priority
Needs evaluation

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (both 132-byte and 202-byte header variants) that...

1 affected package

calibre

Package 22.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-26064

Medium priority
Needs evaluation

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerability that allows arbitrary file writes anywhere the user has write...

1 affected package

calibre

Package 22.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-26967

Medium priority

Not in release

PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and below, there is a critical Heap-based Buffer Overflow vulnerability in PJSIP's H.264 unpacketizer. The bug occurs when processing...

1 affected package

pjproject

Package 22.04 LTS
pjproject Not in release
Show less packages

CVE-2026-26963

Medium priority
Needs evaluation

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.18.0 through 1.18.5 will incorrectly permit traffic from Pods on other nodes when Native Routing, WireGuard and Node Encryption...

1 affected package

golang-github-cilium-ebpf

Package 22.04 LTS
golang-github-cilium-ebpf Needs evaluation
Show less packages

CVE-2026-26958

Medium priority
Needs evaluation

filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographic primitives. In versions 1.1.0 and earlier, MultiScalarMult produces invalid results or undefined behavior if...

1 affected package

golang-filippo-edwards25519

Package 22.04 LTS
golang-filippo-edwards25519 Needs evaluation
Show less packages

CVE-2026-24122

Medium priority

Not in release

Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be considered valid during verification...

1 affected package

cosign

Package 22.04 LTS
cosign Not in release
Show less packages

CVE-2026-26278

Medium priority

Not in release

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited...

1 affected package

node-webfont

Package 22.04 LTS
node-webfont Not in release
Show less packages