Search CVE reports


Toggle filters

281 – 290 of 59858 results

Status is adjusted based on your filters.


CVE-2026-97689

Medium priority
Needs evaluation

urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field...

2 affected packages

python-urllib3, python-pip

Package 16.04 LTS
python-urllib3 Needs evaluation
python-pip Needs evaluation
Show less packages

CVE-2026-97688

Medium priority
Needs evaluation

urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after...

2 affected packages

python-urllib3, python-pip

Package 16.04 LTS
python-urllib3 Needs evaluation
python-pip Needs evaluation
Show less packages

CVE-2026-97687

Medium priority
Needs evaluation

urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE...

2 affected packages

python-urllib3, python-pip

Package 16.04 LTS
python-urllib3 Needs evaluation
python-pip Needs evaluation
Show less packages

CVE-2026-54873

Low priority
Not affected

Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 16.04 LTS
openssl Not affected
openssl-fips —
openssl1.0 —
nodejs Not affected
edk2 Not affected
edk2-hwe —
Show less packages

CVE-2026-42772

Low priority
Not affected

Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 16.04 LTS
openssl Not affected
openssl-fips —
openssl1.0 —
nodejs Not affected
edk2 Not affected
edk2-hwe —
Show less packages

CVE-2026-102601

Medium priority
Needs evaluation

Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats...

1 affected package

php-league-flysystem

Package 16.04 LTS
php-league-flysystem Needs evaluation
Show less packages

CVE-2026-102598

Medium priority
Needs evaluation

Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first...

1 affected package

python-werkzeug

Package 16.04 LTS
python-werkzeug Needs evaluation
Show less packages

CVE-2026-63209

Medium priority
Needs evaluation

compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with...

1 affected package

golang-github-klauspost-compress

Package 16.04 LTS
golang-github-klauspost-compress Needs evaluation
Show less packages

CVE-2026-95520

Medium priority
Needs evaluation

A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext()...

1 affected package

rpm

Package 16.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-19547

Medium priority
Not affected

Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\gs\\ that do not exist...

1 affected package

ghostscript

Package 16.04 LTS
ghostscript Not affected
Show less packages