Search CVE reports


Toggle filters

2591 – 2600 of 34709 results

Status is adjusted based on your filters.


CVE-2026-56822

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP...

1 affected package

netty

Package 26.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-56821

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an...

1 affected package

netty

Package 26.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-61547

Medium priority
Needs evaluation

[Unknown description]

1 affected package

librabbitmq

Package 26.04 LTS
librabbitmq Needs evaluation
Show less packages

CVE-2026-59986

Medium priority
Needs evaluation

[Unknown description]

1 affected package

librabbitmq

Package 26.04 LTS
librabbitmq Needs evaluation
Show less packages

CVE-2026-59921

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied...

1 affected package

netty

Package 26.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-54659

Medium priority

Not in release

Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted...

1 affected package

ruby-pagy

Package 26.04 LTS
ruby-pagy Not in release
Show less packages

CVE-2026-59943

Medium priority

Not in release

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information...

1 affected package

php-dompdf

Package 26.04 LTS
php-dompdf Not in release
Show less packages

CVE-2026-59942

Medium priority

Not in release

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An attacker can crash the PHP process by providing a specially crafted HTML document...

1 affected package

php-dompdf

Package 26.04 LTS
php-dompdf Not in release
Show less packages

CVE-2026-59941

Medium priority

Not in release

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared header dimensions and never bounds width × height before the image is converted...

1 affected package

php-dompdf

Package 26.04 LTS
php-dompdf Not in release
Show less packages

CVE-2026-56722

Medium priority

Not in release

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a  data:  URI,...

1 affected package

php-dompdf

Package 26.04 LTS
php-dompdf Not in release
Show less packages