Search CVE reports


Toggle filters

221 – 230 of 32962 results

Status is adjusted based on your filters.


CVE-2026-69248

Medium priority
Needs evaluation

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a...

1 affected package

python-cryptography

Package 26.04 LTS
python-cryptography Needs evaluation
Show less packages

CVE-2026-69247

Medium priority
Needs evaluation

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a...

1 affected package

python-cryptography

Package 26.04 LTS
python-cryptography Needs evaluation
Show less packages

CVE-2026-69246

Medium priority
Needs evaluation

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push...

1 affected package

guzzle

Package 26.04 LTS
guzzle Needs evaluation
Show less packages

CVE-2026-69245

Medium priority
Needs evaluation

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a...

1 affected package

guzzle

Package 26.04 LTS
guzzle Needs evaluation
Show less packages

CVE-2026-69244

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker...

1 affected package

python-aiohttp

Package 26.04 LTS
python-aiohttp Needs evaluation
Show less packages

CVE-2026-69243

Medium priority
Needs evaluation

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an...

1 affected package

python-aiohttp

Package 26.04 LTS
python-aiohttp Needs evaluation
Show less packages

CVE-2026-69198

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the...

1 affected package

node-ip-address

Package 26.04 LTS
node-ip-address Needs evaluation
Show less packages

CVE-2026-69192

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser,...

1 affected package

node-ip-address

Package 26.04 LTS
node-ip-address Needs evaluation
Show less packages

CVE-2026-69185

Medium priority
Needs evaluation

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer...

1 affected package

node-socket.io-parser

Package 26.04 LTS
node-socket.io-parser Needs evaluation
Show less packages

CVE-2026-69153

Medium priority
Needs evaluation

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an...

1 affected package

node-postcss

Package 26.04 LTS
node-postcss Needs evaluation
Show less packages