Search CVE reports


Toggle filters

2861 – 2870 of 26567 results

Status is adjusted based on your filters.


CVE-2026-29079

Medium priority
Needs evaluation

Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a comment is created using the “unknown element” constructor. The comment’s data are...

1 affected package

lexbor

Package 26.04 LTS
lexbor Needs evaluation
Show less packages

CVE-2026-29078

Medium priority
Needs evaluation

Lexbor is a web browser engine library. Prior to 2.7.0, the ISO‑2022‑JP encoder in Lexbor fails to reset the temporary size variable between iterations. The statement ctx->buffer_used -= size with a stale size = 3 causes an...

1 affected package

lexbor

Package 26.04 LTS
lexbor Needs evaluation
Show less packages

CVE-2026-2859

Medium priority

Not in release

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows unauthenticated users to enumerate existing hosts by observing different HTTP response codes in deploy_agent...

1 affected package

check-mk

Package 26.04 LTS
check-mk Not in release
Show less packages

CVE-2026-2673

Low priority
Fixed

Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS
openssl Fixed
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2026-24097

Medium priority

Not in release

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes...

1 affected package

check-mk

Package 26.04 LTS
check-mk Not in release
Show less packages

CVE-2026-23943

Medium priority
Needs evaluation

Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource Depletion. The SSH transport layer advertises legacy zlib compression by...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-23942

Medium priority
Needs evaluation

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-23941

Medium priority
Needs evaluation

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-2581

Medium priority
Needs evaluation

This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests...

1 affected package

node-undici

Package 26.04 LTS
node-undici Needs evaluation
Show less packages

CVE-2026-2229

Medium priority
Needs evaluation

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it...

1 affected package

node-undici

Package 26.04 LTS
node-undici Needs evaluation
Show less packages