Search CVE reports


Toggle filters

21 – 30 of 51994 results

Status is adjusted based on your filters.


CVE-2026-93690

Medium priority
Needs evaluation

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling...

1 affected package

node-uri-js

Package 22.04 LTS
node-uri-js Needs evaluation
Show less packages

CVE-2026-93687

Medium priority
Needs evaluation

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate...

1 affected package

node-braces

Package 22.04 LTS
node-braces Needs evaluation
Show less packages

CVE-2026-93676

Medium priority
Needs evaluation

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and...

1 affected package

xdg-dbus-proxy

Package 22.04 LTS
xdg-dbus-proxy Needs evaluation
Show less packages

CVE-2026-93658

Medium priority

Not in release

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership...

1 affected package

rust-coreutils

Package 22.04 LTS
rust-coreutils Not in release
Show less packages

CVE-2026-93657

Medium priority

Not in release

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results....

1 affected package

rust-hickory-resolver

Package 22.04 LTS
rust-hickory-resolver Not in release
Show less packages

CVE-2026-93653

Medium priority
Needs evaluation

A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count...

1 affected package

poppler

Package 22.04 LTS
poppler Needs evaluation
Show less packages

CVE-2026-93602

Medium priority

Not in release

rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring...

1 affected package

rust-rustls-webpki

Package 22.04 LTS
rust-rustls-webpki Not in release
Show less packages

CVE-2026-93601

Medium priority

Not in release

rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example,...

1 affected package

rust-rustls-webpki

Package 22.04 LTS
rust-rustls-webpki Not in release
Show less packages

CVE-2026-93600

Medium priority

Not in release

rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced....

1 affected package

rust-rustls-webpki

Package 22.04 LTS
rust-rustls-webpki Not in release
Show less packages

CVE-2026-93599

Medium priority

Not in release

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly...

1 affected package

rust-rustls-webpki

Package 22.04 LTS
rust-rustls-webpki Not in release
Show less packages