Search CVE reports


Toggle filters

131 – 140 of 47927 results

Status is adjusted based on your filters.


CVE-2026-91147

Medium priority
Needs evaluation

A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is...

1 affected package

cockpit

Package 24.04 LTS
cockpit Needs evaluation
Show less packages

CVE-2026-91142

Medium priority
Needs evaluation

A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A...

1 affected package

cockpit

Package 24.04 LTS
cockpit Needs evaluation
Show less packages

CVE-2026-89059

Medium priority
Needs evaluation

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small...

2 affected packages

resteasy, resteasy3.0

Package 24.04 LTS
resteasy Needs evaluation
resteasy3.0 Needs evaluation
Show less packages

CVE-2026-89058

Medium priority
Needs evaluation

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials:...

2 affected packages

resteasy, resteasy3.0

Package 24.04 LTS
resteasy Needs evaluation
resteasy3.0 Needs evaluation
Show less packages

CVE-2026-86049

Medium priority
Needs evaluation

Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing...

1 affected package

jupyter-server

Package 24.04 LTS
jupyter-server Needs evaluation
Show less packages

CVE-2026-86000

Medium priority
Needs evaluation

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character...

1 affected package

soupsieve

Package 24.04 LTS
soupsieve Needs evaluation
Show less packages

CVE-2026-85999

Medium priority
Needs evaluation

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC...

1 affected package

soupsieve

Package 24.04 LTS
soupsieve Needs evaluation
Show less packages

CVE-2026-85721

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses...

1 affected package

async-http-client

Package 24.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-85720

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can...

1 affected package

async-http-client

Package 24.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-85719

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the...

1 affected package

async-http-client

Package 24.04 LTS
async-http-client Needs evaluation
Show less packages