Search CVE reports


Toggle filters

131 – 140 of 65165 results


CVE-2026-33871

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of...

1 affected package

netty

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netty Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-33870

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling...

1 affected package

netty

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netty Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-28369

Medium priority
Needs evaluation

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates...

1 affected package

undertow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
undertow Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-28368

Medium priority
Needs evaluation

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header...

1 affected package

undertow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
undertow Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-28367

Medium priority
Needs evaluation

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache...

1 affected package

undertow

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
undertow Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-4980

Medium priority
Needs evaluation

A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.

1 affected package

inkscape

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
inkscape Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-33750

Medium priority
Needs evaluation

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence...

1 affected package

node-brace-expansion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-brace-expansion Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-33206

Medium priority
Needs evaluation

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar...

1 affected package

calibre

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
calibre Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-33205

Medium priority
Needs evaluation

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's...

1 affected package

calibre

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
calibre Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-28375

Medium priority
Needs evaluation

A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana Not in release Not in release
Show less packages