Search CVE reports


Toggle filters

2881 – 2890 of 26567 results

Status is adjusted based on your filters.


CVE-2025-13462

Medium priority
Needs evaluation

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being...

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 26.04 LTS
python2.7 Not in release
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Not in release
python3.11 Not in release
python3.12 Not in release
python3.13 Not in release
python3.14 Needs evaluation
Show all 12 packages Show less packages

CVE-2026-3497

Medium priority
Ignored

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The...

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS
openssh Not affected
openssh-ssh1 Ignored
Show less packages

CVE-2026-28356

Medium priority
Needs evaluation

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can...

1 affected package

multipart

Package 26.04 LTS
multipart Needs evaluation
Show less packages

CVE-2026-27940

Medium priority
Needs evaluation

llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized heap allocation. Using the subsequent fread()...

1 affected package

llama.cpp

Package 26.04 LTS
llama.cpp Needs evaluation
Show less packages

CVE-2026-3099

Low priority
Vulnerable

A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This...

2 affected packages

libsoup2.4, libsoup3

Package 26.04 LTS
libsoup2.4 Vulnerable
libsoup3 Vulnerable
Show less packages

CVE-2026-4016

Medium priority

Not in release

A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_process of the file src/filters/load_svg.c of the component SVG Parser. The manipulation leads to out-of-bounds...

1 affected package

gpac

Package 26.04 LTS
gpac Not in release
Show less packages

CVE-2026-4015

Medium priority

Not in release

A weakness has been identified in GPAC 26.03-DEV. Affected is the function txtin_process_texml of the file src/filters/load_text.c of the component TeXML File Parser. Executing a manipulation can lead to stack-based...

1 affected package

gpac

Package 26.04 LTS
gpac Not in release
Show less packages

CVE-2026-3994

Medium priority
Needs evaluation

A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::initialize_sections of the file src/input-files.cc of the component Object File Handler. Performing a...

1 affected package

mold

Package 26.04 LTS
mold Needs evaluation
Show less packages

CVE-2026-3979

Medium priority
Needs evaluation

A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the file quickjs.c. This manipulation causes use after free. The attack requires local access. The exploit has been...

1 affected package

quickjs

Package 26.04 LTS
quickjs Needs evaluation
Show less packages

CVE-2026-2808

Medium priority

Not in release

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11...

1 affected package

consul

Package 26.04 LTS
consul Not in release
Show less packages