Search CVE reports


Toggle filters

101 – 110 of 33622 results

Status is adjusted based on your filters.


CVE-2026-35406

Medium priority
Needs evaluation

Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100%...

1 affected package

aardvark-dns

Package 24.04 LTS
aardvark-dns Needs evaluation
Show less packages

CVE-2026-34582

Medium priority
Needs evaluation

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client...

2 affected packages

botan, botan3

Package 24.04 LTS
botan Needs evaluation
botan3 Not in release
Show less packages

CVE-2026-34580

Medium priority
Needs evaluation

Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching...

2 affected packages

botan3, botan

Package 24.04 LTS
botan3 Not in release
botan Needs evaluation
Show less packages

CVE-2026-34079

Medium priority
Needs evaluation

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache...

1 affected package

flatpak

Package 24.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-34078

Medium priority
Needs evaluation

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run...

1 affected package

flatpak

Package 24.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-34080

Medium priority
Needs evaluation

xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop...

1 affected package

xdg-dbus-proxy

Package 24.04 LTS
xdg-dbus-proxy Needs evaluation
Show less packages

CVE-2026-29181

Medium priority
Needs evaluation

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker...

1 affected package

golang-opentelemetry-otel

Package 24.04 LTS
golang-opentelemetry-otel Needs evaluation
Show less packages

CVE-2026-39395

Medium priority

Not in release

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads...

1 affected package

cosign

Package 24.04 LTS
cosign Not in release
Show less packages

CVE-2026-39373

Medium priority
Needs evaluation

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for...

1 affected package

python-jwcrypto

Package 24.04 LTS
python-jwcrypto Needs evaluation
Show less packages

CVE-2026-39324

Medium priority
Needs evaluation

Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryption fails, the implementation...

2 affected packages

ruby-rack-session, ruby-rack

Package 24.04 LTS
ruby-rack-session Not in release
ruby-rack Needs evaluation
Show less packages