Search CVE reports


Toggle filters

1 – 10 of 39027 results

Status is adjusted based on your filters.


CVE-2026-95625

Medium priority
Needs evaluation

The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains the version number, download URL, and signature -- is fetched...

1 affected package

minisign

Package 26.04 LTS
minisign Needs evaluation
Show less packages

CVE-2026-82331

Medium priority

Not in release

Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the...

1 affected package

buildstream

Package 26.04 LTS
buildstream Not in release
Show less packages

CVE-2026-91777

Medium priority
Needs evaluation

Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths...

1 affected package

jackson-databind

Package 26.04 LTS
jackson-databind Needs evaluation
Show less packages

CVE-2026-91776

Medium priority
Needs evaluation

TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for...

1 affected package

jackson-databind

Package 26.04 LTS
jackson-databind Needs evaluation
Show less packages

CVE-2026-89425

Medium priority
Needs evaluation

UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the...

1 affected package

jackson-core

Package 26.04 LTS
jackson-core Needs evaluation
Show less packages

CVE-2026-95897

Medium priority
Needs evaluation

A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loader. Such manipulation leads to deserialization. The attack can be...

1 affected package

dask

Package 26.04 LTS
dask Needs evaluation
Show less packages

CVE-2026-96284

Medium priority
Not affected

security update

1 affected package

flatpak

Package 26.04 LTS
flatpak Not affected
Show less packages

CVE-2026-96283

Medium priority
Not affected

security update

1 affected package

flatpak

Package 26.04 LTS
flatpak Not affected
Show less packages

CVE-2026-96282

Medium priority
Needs evaluation

security update

1 affected package

flatpak

Package 26.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-96281

Medium priority
Needs evaluation

security update

1 affected package

flatpak

Package 26.04 LTS
flatpak Needs evaluation
Show less packages