Search CVE reports


Toggle filters

461 – 470 of 37500 results

Status is adjusted based on your filters.


CVE-2026-87910

Medium priority
Needs evaluation

When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to...

12 affected packages

pypy3, python2.7, python3.4, python3.5, python3.6...

Package 26.04 LTS
pypy3 Needs evaluation
python2.7 Not in release
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Not in release
python3.11 Not in release
python3.12 Not in release
python3.14 Needs evaluation
Show all 12 packages Show less packages

CVE-2026-87908

Medium priority
Needs evaluation

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single...

1 affected package

node-multiparty

Package 26.04 LTS
node-multiparty Needs evaluation
Show less packages

CVE-2026-87859

Medium priority
Needs evaluation

morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that...

1 affected package

node-morgan

Package 26.04 LTS
node-morgan Needs evaluation
Show less packages

CVE-2026-87776

Medium priority
Needs evaluation

compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never...

1 affected package

node-compression

Package 26.04 LTS
node-compression Needs evaluation
Show less packages

CVE-2026-87106

Medium priority

Not in release

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the...

1 affected package

consul

Package 26.04 LTS
consul Not in release
Show less packages

CVE-2026-87020

Medium priority
Needs evaluation

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

1 affected package

orthanc

Package 26.04 LTS
orthanc Needs evaluation
Show less packages

CVE-2026-86776

Medium priority
Needs evaluation

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger...

1 affected package

keepass2

Package 26.04 LTS
keepass2 Needs evaluation
Show less packages

CVE-2026-85979

Medium priority
Needs evaluation

Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell...

1 affected package

puppetserver

Package 26.04 LTS
puppetserver Needs evaluation
Show less packages

CVE-2026-84939

Medium priority
Needs evaluation

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by...

1 affected package

libfreemarker-java

Package 26.04 LTS
libfreemarker-java Needs evaluation
Show less packages

CVE-2026-83530

Medium priority
Needs evaluation

A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit...

1 affected package

golang-github-google-cel-go

Package 26.04 LTS
golang-github-google-cel-go Needs evaluation
Show less packages