Search CVE reports


Toggle filters

31 – 40 of 45244 results

Status is adjusted based on your filters.


CVE-2026-65107

Medium priority
Needs evaluation

[Fix sbcast shared objects skipping credential verification, Fix possible slurmd crash on invalid sbcast filenames]

1 affected package

slurm-wlm

Package 24.04 LTS
slurm-wlm Needs evaluation
Show less packages

CVE-2026-59696

Medium priority
Needs evaluation

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade availability by supplying a URI whose port component is a very long run of digits. uri_string:get_port/1...

1 affected package

erlang

Package 24.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-56855

Medium priority
Needs evaluation

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then,...

10 affected packages

golang-1.17, golang-1.20, golang-1.21, golang-1.22, golang-1.23...

Package 24.04 LTS
golang-1.17 Not in release
golang-1.20 Not in release
golang-1.21 Needs evaluation
golang-1.22 Needs evaluation
golang-1.23 Needs evaluation
golang-1.24 Needs evaluation
golang-1.25 Not in release
golang-1.26 Not in release
golang-1.27 Not in release
golang-defaults Needs evaluation
Show all 10 packages Show less packages

CVE-2026-55951

Medium priority
Needs evaluation

The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header...

1 affected package

erlang

Package 24.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-53683

Medium priority
Needs evaluation

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is...

1 affected package

freeipa

Package 24.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-53682

Medium priority

Not in release

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology...

1 affected package

dogtag-pki

Package 24.04 LTS
dogtag-pki Not in release
Show less packages

CVE-2026-53600

Medium priority
Needs evaluation

async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension header (a GNU longname L, a GNU longlink K, or a PAX x/g...

1 affected package

rust-async-tar

Package 24.04 LTS
rust-async-tar Needs evaluation
Show less packages

CVE-2026-17615

Medium priority
Needs evaluation

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration...

2 affected packages

resteasy, resteasy3.0

Package 24.04 LTS
resteasy Needs evaluation
resteasy3.0 Needs evaluation
Show less packages

CVE-2026-84642

Medium priority
Needs evaluation

(The values of the mail.allowed_attachment_hostnames advanced config se ...)

1 affected package

thunderbird

Package 24.04 LTS
thunderbird Needs evaluation
Show less packages

CVE-2026-84641

Medium priority
Needs evaluation

(A malicious IMAP server can trigger use-after-free and heap-memory dis ...)

1 affected package

thunderbird

Package 24.04 LTS
thunderbird Needs evaluation
Show less packages