Search CVE reports


Toggle filters

1 – 10 of 283 results


CVE-2026-48932

Medium priority
Needs evaluation

A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend...

1 affected package

nodejs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nodejs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-75803

Low priority

Some fixes available 4 of 9

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Fixed Not in release — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Vulnerable Vulnerable Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-63076

Medium priority

Some fixes available 4 of 9

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Fixed Not in release — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Vulnerable Vulnerable Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-63075

Low priority

Some fixes available 1 of 5

Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-63074

Low priority

Some fixes available 4 of 9

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Fixed Not in release — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-63073

Low priority

Some fixes available 1 of 5

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-63072

Medium priority

Some fixes available 9 of 18

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Fixed Not in release — —
openssl1.0 Not in release Not in release Not in release — Fixed
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-54874

Low priority

Some fixes available 9 of 19

Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Fixed Not in release — —
openssl1.0 Not in release Not in release Not in release — Fixed
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-18798

Medium priority

Some fixes available 1 of 5

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-14457

Low priority

Some fixes available 1 of 5

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages