Search CVE reports


Toggle filters

181 – 190 of 49237 results

Status is adjusted based on your filters.


CVE-2026-97688

Medium priority
Needs evaluation

urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after...

2 affected packages

python-urllib3, python-pip

Package 24.04 LTS
python-urllib3 Needs evaluation
python-pip Needs evaluation
Show less packages

CVE-2026-97687

Medium priority
Needs evaluation

urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE...

2 affected packages

python-urllib3, python-pip

Package 24.04 LTS
python-urllib3 Needs evaluation
python-pip Needs evaluation
Show less packages

CVE-2026-54873

Low priority
Not affected

Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 24.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
edk2-hwe Not in release
Show less packages

CVE-2026-42772

Low priority
Not affected

Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 24.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
edk2-hwe Not in release
Show less packages

CVE-2026-102601

Medium priority
Needs evaluation

Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats...

1 affected package

php-league-flysystem

Package 24.04 LTS
php-league-flysystem Needs evaluation
Show less packages

CVE-2026-102598

Medium priority
Needs evaluation

Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first...

1 affected package

python-werkzeug

Package 24.04 LTS
python-werkzeug Needs evaluation
Show less packages

CVE-2026-63209

Medium priority
Needs evaluation

compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with...

1 affected package

golang-github-klauspost-compress

Package 24.04 LTS
golang-github-klauspost-compress Needs evaluation
Show less packages

CVE-2026-96869

Medium priority
Ignored

Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 24.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Ignored
mozjs115 Ignored
Show all 9 packages Show less packages

CVE-2026-76875

Medium priority
Needs evaluation

PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to...

1 affected package

pypy3

Package 24.04 LTS
pypy3 Needs evaluation
Show less packages

CVE-2026-100831

Medium priority
Ignored

Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 24.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Ignored
mozjs115 Ignored
Show all 9 packages Show less packages