Search CVE reports


Toggle filters

181 – 190 of 59631 results

Status is adjusted based on your filters.


CVE-2026-100664

Medium priority
Needs evaluation

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1...

1 affected package

netty

Package 16.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-100663

Medium priority
Needs evaluation

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3...

1 affected package

netty

Package 16.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-100662

Medium priority
Needs evaluation

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder (QpackEncoderHandler, installed...

1 affected package

netty

Package 16.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-100661

Medium priority
Needs evaluation

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound...

1 affected package

netty

Package 16.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-100660

Medium priority
Needs evaluation

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker for every encoded...

1 affected package

netty

Package 16.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-100659

Medium priority
Needs evaluation

Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 requirement that the :authority pseudo-header field and a literal host header field, when both present,...

1 affected package

netty

Package 16.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-92842

Medium priority
Needs evaluation

The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 16.04 LTS
php5 —
php7.0 Needs evaluation
php7.2 —
php7.4 —
php8.1 —
php8.3 —
php8.5 —
Show all 7 packages Show less packages

CVE-2026-91768

Medium priority
Needs evaluation

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 16.04 LTS
php5 —
php7.0 Needs evaluation
php7.2 —
php7.4 —
php8.1 —
php8.3 —
php8.5 —
Show all 7 packages Show less packages

CVE-2026-91769

Medium priority
Needs evaluation

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 16.04 LTS
php5 —
php7.0 Needs evaluation
php7.2 —
php7.4 —
php8.1 —
php8.3 —
php8.5 —
Show all 7 packages Show less packages

CVE-2026-91767

Medium priority
Needs evaluation

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 16.04 LTS
php5 —
php7.0 Needs evaluation
php7.2 —
php7.4 —
php8.1 —
php8.3 —
php8.5 —
Show all 7 packages Show less packages