Search CVE reports


Toggle filters

1001 – 1010 of 47891 results

Status is adjusted based on your filters.


CVE-2026-47192

Medium priority
Needs evaluation

kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding configuration includes prior to validating signatures of those repositories....

1 affected package

kas

Package 22.04 LTS
kas Needs evaluation
Show less packages

CVE-2026-47191

Medium priority
Needs evaluation

kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit...

1 affected package

kas

Package 22.04 LTS
kas Needs evaluation
Show less packages

CVE-2026-46603

Medium priority
Needs evaluation

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via...

1 affected package

golang-golang-x-image

Package 22.04 LTS
golang-golang-x-image Needs evaluation
Show less packages

CVE-2026-13002

Medium priority
Vulnerable

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution...

1 affected package

dnsmasq

Package 22.04 LTS
dnsmasq Vulnerable
Show less packages

CVE-2026-19879

Medium priority
Needs evaluation

A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes when writing HTTP response...

1 affected package

undertow

Package 22.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-73051

Medium priority

Not in release

actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can...

1 affected package

rust-actix-http

Package 22.04 LTS
rust-actix-http Not in release
Show less packages

CVE-2026-72817

Medium priority
Needs evaluation

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating...

1 affected package

golang-github-go-chi-chi

Package 22.04 LTS
golang-github-go-chi-chi Needs evaluation
Show less packages

CVE-2026-72816

Medium priority
Needs evaluation

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites...

1 affected package

golang-github-go-chi-chi

Package 22.04 LTS
golang-github-go-chi-chi Needs evaluation
Show less packages

CVE-2026-72815

Medium priority
Needs evaluation

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based...

1 affected package

golang-github-go-chi-chi

Package 22.04 LTS
golang-github-go-chi-chi Needs evaluation
Show less packages

CVE-2026-72814

Medium priority

Not in release

The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path;...

1 affected package

rust-actix-files

Package 22.04 LTS
rust-actix-files Not in release
Show less packages