Search CVE reports


Toggle filters

1041 – 1050 of 48104 results

Status is adjusted based on your filters.


CVE-2026-59944

Medium priority
Needs evaluation

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates...

1 affected package

composer

Package 24.04 LTS
composer Needs evaluation
Show less packages

CVE-2026-42784

Medium priority
Needs evaluation

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion...

1 affected package

rust-sequoia-openpgp

Package 24.04 LTS
rust-sequoia-openpgp Needs evaluation
Show less packages

CVE-2026-92627

Medium priority
Needs evaluation

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with...

1 affected package

hdf5

Package 24.04 LTS
hdf5 Needs evaluation
Show less packages

CVE-2026-19607

Medium priority
Needs evaluation

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an...

1 affected package

python-keycloak

Package 24.04 LTS
python-keycloak Needs evaluation
Show less packages

CVE-2026-80274

Medium priority
Needs evaluation

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 24.04 LTS
bind9 Needs evaluation
isc-dhcp Needs evaluation
bind9-libs Not in release
Show less packages

CVE-2026-77119

Medium priority
Needs evaluation

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50,...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 24.04 LTS
bind9 Needs evaluation
isc-dhcp Needs evaluation
bind9-libs Not in release
Show less packages

CVE-2026-76825

Medium priority
Needs evaluation

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals...

1 affected package

restrictedpython

Package 24.04 LTS
restrictedpython Needs evaluation
Show less packages

CVE-2026-76163

Medium priority
Needs evaluation

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 24.04 LTS
bind9 Needs evaluation
isc-dhcp Needs evaluation
bind9-libs Not in release
Show less packages

CVE-2026-75029

Medium priority
Needs evaluation

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set,...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 24.04 LTS
bind9 Needs evaluation
isc-dhcp Needs evaluation
bind9-libs Not in release
Show less packages

CVE-2026-19668

Medium priority
Needs evaluation

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 24.04 LTS
bind9 Needs evaluation
isc-dhcp Needs evaluation
bind9-libs Not in release
Show less packages