Search CVE reports
101 – 110 of 44355 results
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**,...
1 affected package
nodejs
| Package | 20.04 LTS |
|---|---|
| nodejs | Needs evaluation |
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with...
1 affected package
python-django
| Package | 20.04 LTS |
|---|---|
| python-django | Needs evaluation |
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects...
1 affected package
python-django
| Package | 20.04 LTS |
|---|---|
| python-django | Needs evaluation |
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which...
1 affected package
python-django
| Package | 20.04 LTS |
|---|---|
| python-django | Needs evaluation |
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor....
1 affected package
python-django
| Package | 20.04 LTS |
|---|---|
| python-django | Needs evaluation |
The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass. The earlier fix wired...
1 affected package
jackson-core
| Package | 20.04 LTS |
|---|---|
| jackson-core | Needs evaluation |
The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses...
1 affected package
jackson-core
| Package | 20.04 LTS |
|---|---|
| jackson-core | Needs evaluation |
Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.
9 affected packages
firefox, thunderbird, mozjs38, mozjs52, mozjs68...
| Package | 20.04 LTS |
|---|---|
| firefox | — |
| thunderbird | — |
| mozjs38 | — |
| mozjs52 | Ignored |
| mozjs68 | Ignored |
| mozjs78 | — |
| mozjs91 | — |
| mozjs102 | — |
| mozjs115 | — |
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed...
2 affected packages
jetty12, jetty9
| Package | 20.04 LTS |
|---|---|
| jetty12 | — |
| jetty9 | Needs evaluation |
Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads.
1 affected package
rlottie
| Package | 20.04 LTS |
|---|---|
| rlottie | Needs evaluation |