Search CVE reports


Toggle filters

1481 – 1490 of 37626 results

Status is adjusted based on your filters.


CVE-2026-82522

Medium priority
Needs evaluation

libjxl before 0.12 contains an integer underflow vulnerability in the container box parser that allows remote attackers to inject arbitrary metadata by exploiting 64-bit box size truncation to size_t on 32-bit platforms. Attackers...

1 affected package

jpeg-xl

Package 26.04 LTS
jpeg-xl Needs evaluation
Show less packages

CVE-2026-84838

Medium priority
Needs evaluation

A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell...

1 affected package

rpm

Package 26.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-84837

Medium priority
Needs evaluation

A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in...

1 affected package

rpm

Package 26.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-78689

Medium priority
Needs evaluation

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected...

1 affected package

libnginx-mod-js

Package 26.04 LTS
libnginx-mod-js Needs evaluation
Show less packages

CVE-2026-78410

Medium priority
Needs evaluation

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor...

1 affected package

util-linux

Package 26.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-78409

Medium priority
Needs evaluation

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep...

1 affected package

util-linux

Package 26.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-78408

Medium priority
Needs evaluation

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations...

1 affected package

util-linux

Package 26.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-78222

Medium priority
Needs evaluation

A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the...

1 affected package

libnginx-mod-js

Package 26.04 LTS
libnginx-mod-js Needs evaluation
Show less packages

CVE-2026-53600

Medium priority

Not in release

async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension header (a GNU longname L, a GNU longlink K, or a PAX x/g...

1 affected package

rust-async-tar

Package 26.04 LTS
rust-async-tar Not in release
Show less packages

CVE-2026-18329

Medium priority
Needs evaluation

Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation...

1 affected package

libnginx-mod-js

Package 26.04 LTS
libnginx-mod-js Needs evaluation
Show less packages