Search CVE reports


Toggle filters

3001 – 3010 of 35557 results

Status is adjusted based on your filters.


CVE-2026-2808

Medium priority

Not in release

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11...

1 affected package

consul

Package 24.04 LTS
consul Not in release
Show less packages

CVE-2026-31988

Medium priority
Needs evaluation

yauzl (aka Yet Another Unzip Library) version 3.2.0 for Node.js contains an off-by-one error in the NTFS extended timestamp extra field parser within the getLastModDate() function. The while loop condition checks cursor...

1 affected package

node-yauzl

Package 24.04 LTS
node-yauzl Needs evaluation
Show less packages

CVE-2026-3950

Medium priority
Not affected

A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack...

1 affected package

libheif

Package 24.04 LTS
libheif Not affected
Show less packages

CVE-2026-31958

Medium priority
Fixed

Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing...

1 affected package

python-tornado

Package 24.04 LTS
python-tornado Fixed
Show less packages

CVE-2026-31900

Medium priority
Needs evaluation

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the...

1 affected package

black

Package 24.04 LTS
black Needs evaluation
Show less packages

CVE-2026-3949

Medium priority
Not affected

A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the file libheif/plugins/decoder_vvdec.cc of the component HEIF File Parser. Executing a manipulation of the argument...

1 affected package

libheif

Package 24.04 LTS
libheif Not affected
Show less packages

CVE-2026-31870

Medium priority
Needs evaluation

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses the streaming API (httplib::stream::Get, httplib::stream::Post, etc.), the library...

1 affected package

cpp-httplib

Package 24.04 LTS
cpp-httplib Needs evaluation
Show less packages

CVE-2026-3805

Medium priority
Not affected

When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.

1 affected package

curl

Package 24.04 LTS
curl Not affected
Show less packages

CVE-2026-3784

Low priority
Fixed

curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection.

1 affected package

curl

Package 24.04 LTS
curl Fixed
Show less packages

CVE-2026-3783

Medium priority
Fixed

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request...

1 affected package

curl

Package 24.04 LTS
curl Fixed
Show less packages