Search CVE reports
2941 – 2950 of 26567 results
Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_regexp matcher in vars.go:337 double-expands user-controlled input through the Caddy replacer. When vars_regexp...
1 affected package
caddy
| Package | 26.04 LTS |
|---|---|
| caddy | Needs evaluation |
Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injection and privilege escalation....
1 affected package
caddy
| Package | 26.04 LTS |
|---|---|
| caddy | Needs evaluation |
league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and...
1 affected package
php-league-commonmark
| Package | 26.04 LTS |
|---|---|
| php-league-commonmark | Vulnerable |
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which...
1 affected package
node-tar
| Package | 26.04 LTS |
|---|---|
| node-tar | Needs evaluation |
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib uses std::regex (libstdc++) to parse RFC 5987 encoded filename* values in multipart...
1 affected package
cpp-httplib
| Package | 26.04 LTS |
|---|---|
| cpp-httplib | Needs evaluation |
Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration...
1 affected package
zookeeper
| Package | 26.04 LTS |
|---|---|
| zookeeper | Needs evaluation |
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid...
1 affected package
zookeeper
| Package | 26.04 LTS |
|---|---|
| zookeeper | Needs evaluation |
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of...
1 affected package
dpkg
| Package | 26.04 LTS |
|---|---|
| dpkg | Not affected |
Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been...
3 affected packages
golang-1.24, golang-1.25, golang-1.26
| Package | 26.04 LTS |
|---|---|
| golang-1.24 | Needs evaluation |
| golang-1.25 | Needs evaluation |
| golang-1.26 | Needs evaluation |
On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to...
3 affected packages
golang-1.24, golang-1.25, golang-1.26
| Package | 26.04 LTS |
|---|---|
| golang-1.24 | Needs evaluation |
| golang-1.25 | Needs evaluation |
| golang-1.26 | Needs evaluation |