Search CVE reports


Toggle filters

931 – 940 of 39983 results

Status is adjusted based on your filters.


CVE-2026-5545

Medium priority
Vulnerable

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.

1 affected package

curl

Package 20.04 LTS
curl Vulnerable
Show less packages

CVE-2026-4873

Low priority
Vulnerable

A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent...

1 affected package

curl

Package 20.04 LTS
curl Vulnerable
Show less packages

CVE-2026-22741

Medium priority
Needs evaluation

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or...

1 affected package

libspring-java

Package 20.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-22740

Medium priority
Needs evaluation

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows...

1 affected package

libspring-java

Package 20.04 LTS
libspring-java Needs evaluation
Show less packages

CVE-2026-40687

Medium priority
Needs evaluation

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from...

1 affected package

exim4

Package 20.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-40686

Medium priority
Needs evaluation

In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced...

1 affected package

exim4

Package 20.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-40685

Medium priority
Needs evaluation

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.

1 affected package

exim4

Package 20.04 LTS
exim4 Needs evaluation
Show less packages

CVE-2026-40684

Medium priority
Not affected

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

1 affected package

exim4

Package 20.04 LTS
exim4 Not affected
Show less packages

CVE-2026-7168

Medium priority
Needs evaluation

cross-proxy Digest auth state leak

1 affected package

curl

Package 20.04 LTS
curl Needs evaluation
Show less packages

CVE-2026-7111

Medium priority
Needs evaluation

Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods...

1 affected package

libtext-csv-xs-perl

Package 20.04 LTS
libtext-csv-xs-perl Needs evaluation
Show less packages