Search CVE reports


Toggle filters

1101 – 1110 of 55785 results

Status is adjusted based on your filters.


CVE-2026-56858

Medium priority
Needs evaluation

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 16.04 LTS
golang
golang-1.6 Needs evaluation
golang-1.8
golang-1.9
golang-1.10 Needs evaluation
golang-1.13 Needs evaluation
golang-1.14
golang-1.16
golang-1.17
golang-1.18 Needs evaluation
golang-1.20
golang-1.21
golang-1.22
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2026-56853

Medium priority
Needs evaluation

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 16.04 LTS
golang
golang-1.6 Needs evaluation
golang-1.8
golang-1.9
golang-1.10 Needs evaluation
golang-1.13 Needs evaluation
golang-1.14
golang-1.16
golang-1.17
golang-1.18 Needs evaluation
golang-1.20
golang-1.21
golang-1.22
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2026-33818

Medium priority
Needs evaluation

Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.

16 affected packages

golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...

Package 16.04 LTS
golang
golang-1.6 Needs evaluation
golang-1.8
golang-1.9
golang-1.10 Needs evaluation
golang-1.13 Needs evaluation
golang-1.14
golang-1.16
golang-1.17
golang-1.18 Needs evaluation
golang-1.20
golang-1.21
golang-1.22
golang-1.23
golang-1.24
golang-1.25
Show all 16 packages Show less packages

CVE-2026-73648

Medium priority
Needs evaluation

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href,...

1 affected package

ruby-rails-html-sanitizer

Package 16.04 LTS
ruby-rails-html-sanitizer Needs evaluation
Show less packages

CVE-2026-73566

Medium priority
Needs evaluation

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when...

1 affected package

node-tar

Package 16.04 LTS
node-tar Needs evaluation
Show less packages

CVE-2022-4993

Medium priority
Needs evaluation

HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket...

1 affected package

libhtml-formhandler-perl

Package 16.04 LTS
libhtml-formhandler-perl Needs evaluation
Show less packages

CVE-2026-73515

Medium priority
Needs evaluation

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata...

1 affected package

postgis

Package 16.04 LTS
postgis Needs evaluation
Show less packages

CVE-2026-19487

Medium priority
Needs evaluation

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass. The prescan walks the subject for positions where the full...

1 affected package

perl

Package 16.04 LTS
perl Needs evaluation
Show less packages

CVE-2026-73508

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(),...

1 affected package

netty

Package 16.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-73507

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so...

1 affected package

netty

Package 16.04 LTS
netty Needs evaluation
Show less packages