Search CVE reports


Toggle filters

1 – 10 of 950 results


CVE-2026-88387

Medium priority
Needs evaluation

LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, TIFF, or DNG file can supply an attacker-controlled...

8 affected packages

libraw, ufraw, darktable, exactimage, dcraw...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ufraw Not in release Not in release Not in release — Needs evaluation
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
digikam Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 8 packages Show less packages

CVE-2026-84939

Medium priority
Needs evaluation

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by...

1 affected package

libfreemarker-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libfreemarker-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-86435

Medium priority
Needs evaluation

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-86434

Medium priority
Needs evaluation

league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-86433

Medium priority
Needs evaluation

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() performs quadratic-time sibling list scanning. Unauthenticated...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-86432

Medium priority
Needs evaluation

commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-86431

Medium priority
Needs evaluation

league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C form feed byte...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-86430

Medium priority
Needs evaluation

league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-86429

Medium priority
Needs evaluation

The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-86428

Medium priority
Needs evaluation

commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages