Search CVE reports


Toggle filters

1591 – 1600 of 26183 results

Status is adjusted based on your filters.


CVE-2026-4660

Medium priority

Not in release

HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This...

1 affected package

golang-github-hashicorp-go-getter

Package 26.04 LTS
golang-github-hashicorp-go-getter Not in release
Show less packages

CVE-2026-34179

Medium priority
Vulnerable

In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS...

2 affected packages

lxd, incus

Package 26.04 LTS
lxd Not in release
incus Vulnerable
Show less packages

CVE-2026-34178

Medium priority
Vulnerable

In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, a separate file in the same...

2 affected packages

lxd, incus

Package 26.04 LTS
lxd Not in release
incus Vulnerable
Show less packages

CVE-2026-34177

Medium priority
Not affected

Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under...

2 affected packages

lxd, incus

Package 26.04 LTS
lxd Not in release
incus Not affected
Show less packages

CVE-2026-34757

Medium priority
Not affected

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS,...

5 affected packages

libpng, libpng1.6, firefox, thunderbird, chromium-browser

Package 26.04 LTS
libpng Not in release
libpng1.6 Not affected
firefox Not affected
thunderbird Not affected
chromium-browser Not affected
Show less packages

CVE-2026-40026

Medium priority
Needs evaluation

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack...

1 affected package

sleuthkit

Package 26.04 LTS
sleuthkit Needs evaluation
Show less packages

CVE-2026-40025

Medium priority
Needs evaluation

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without bounds checking, causing heap...

1 affected package

sleuthkit

Package 26.04 LTS
sleuthkit Needs evaluation
Show less packages

CVE-2026-40024

Medium priority
Needs evaluation

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths...

1 affected package

sleuthkit

Package 26.04 LTS
sleuthkit Needs evaluation
Show less packages

CVE-2026-39883

Medium priority
Needs evaluation

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the...

1 affected package

golang-opentelemetry-otel

Package 26.04 LTS
golang-opentelemetry-otel Needs evaluation
Show less packages

CVE-2026-39882

Medium priority
Needs evaluation

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for...

1 affected package

golang-opentelemetry-otel

Package 26.04 LTS
golang-opentelemetry-otel Needs evaluation
Show less packages