Search CVE reports


Toggle filters

1721 – 1730 of 39363 results

Status is adjusted based on your filters.


CVE-2026-35406

Medium priority

Not in release

Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100%...

1 affected package

aardvark-dns

Package 22.04 LTS
aardvark-dns Not in release
Show less packages

CVE-2026-34582

Medium priority
Needs evaluation

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client...

2 affected packages

botan, botan3

Package 22.04 LTS
botan Needs evaluation
botan3 Not in release
Show less packages

CVE-2026-34580

Medium priority
Needs evaluation

Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching...

2 affected packages

botan3, botan

Package 22.04 LTS
botan3 Not in release
botan Needs evaluation
Show less packages

CVE-2026-34079

Medium priority
Needs evaluation

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache...

1 affected package

flatpak

Package 22.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-34078

Medium priority
Needs evaluation

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run...

1 affected package

flatpak

Package 22.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-34080

Medium priority
Fixed

xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop...

1 affected package

xdg-dbus-proxy

Package 22.04 LTS
xdg-dbus-proxy Fixed
Show less packages

CVE-2026-29181

Medium priority
Needs evaluation

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker...

1 affected package

golang-opentelemetry-otel

Package 22.04 LTS
golang-opentelemetry-otel Needs evaluation
Show less packages

CVE-2026-39395

Medium priority

Not in release

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads...

1 affected package

cosign

Package 22.04 LTS
cosign Not in release
Show less packages

CVE-2026-39373

Medium priority
Needs evaluation

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for...

1 affected package

python-jwcrypto

Package 22.04 LTS
python-jwcrypto Needs evaluation
Show less packages

CVE-2026-39324

Medium priority
Not affected

Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryption fails, the implementation...

2 affected packages

ruby-rack, ruby-rack-session

Package 22.04 LTS
ruby-rack Not affected
ruby-rack-session Not in release
Show less packages