Search CVE reports


Toggle filters

1211 – 1220 of 47099 results

Status is adjusted based on your filters.


CVE-2026-87819

Medium priority
Needs evaluation

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field...

1 affected package

python-git

Package 24.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-87818

Medium priority
Needs evaluation

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to...

1 affected package

python-git

Package 24.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-87817

Medium priority
Needs evaluation

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by...

1 affected package

python-git

Package 24.04 LTS
python-git Needs evaluation
Show less packages

CVE-2026-74761

Medium priority
Needs evaluation

Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ AllĀ on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue...

1 affected package

activemq

Package 24.04 LTS
activemq Needs evaluation
Show less packages

CVE-2026-87795

Medium priority
Needs evaluation

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap...

1 affected package

zstd-jni-java

Package 24.04 LTS
zstd-jni-java Needs evaluation
Show less packages

CVE-2026-86776

Medium priority
Needs evaluation

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger...

1 affected package

keepass2

Package 24.04 LTS
keepass2 Needs evaluation
Show less packages

CVE-2026-87766

Medium priority
Vulnerable

A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching...

1 affected package

bubblewrap

Package 24.04 LTS
bubblewrap Vulnerable
Show less packages

CVE-2026-87737

Medium priority
Needs evaluation

An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.

1 affected package

ocaml-mirage-crypto

Package 24.04 LTS
ocaml-mirage-crypto Needs evaluation
Show less packages

CVE-2026-87736

Medium priority
Needs evaluation

An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.

1 affected package

ocaml-mirage-crypto

Package 24.04 LTS
ocaml-mirage-crypto Needs evaluation
Show less packages

CVE-2026-87735

Medium priority
Needs evaluation

An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption.

1 affected package

ocaml-mirage-crypto

Package 24.04 LTS
ocaml-mirage-crypto Needs evaluation
Show less packages