Search CVE reports


Toggle filters

831 – 840 of 46140 results

Status is adjusted based on your filters.


CVE-2026-24033

Medium priority
Needs evaluation

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14. Users are...

1 affected package

trafficserver

Package 22.04 LTS
trafficserver Needs evaluation
Show less packages

CVE-2026-22068

Medium priority
Needs evaluation

Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or...

1 affected package

trafficserver

Package 22.04 LTS
trafficserver Needs evaluation
Show less packages

CVE-2026-56822

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-56821

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-61547

Medium priority
Needs evaluation

[Unknown description]

1 affected package

librabbitmq

Package 22.04 LTS
librabbitmq Needs evaluation
Show less packages

CVE-2026-59986

Medium priority
Needs evaluation

[Unknown description]

1 affected package

librabbitmq

Package 22.04 LTS
librabbitmq Needs evaluation
Show less packages

CVE-2026-59921

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied...

1 affected package

netty

Package 22.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-54659

Medium priority

Not in release

Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted...

1 affected package

ruby-pagy

Package 22.04 LTS
ruby-pagy Not in release
Show less packages

CVE-2026-59943

Medium priority
Needs evaluation

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information...

1 affected package

php-dompdf

Package 22.04 LTS
php-dompdf Needs evaluation
Show less packages

CVE-2026-59942

Medium priority
Needs evaluation

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An attacker can crash the PHP process by providing a specially crafted HTML document...

1 affected package

php-dompdf

Package 22.04 LTS
php-dompdf Needs evaluation
Show less packages