Search CVE reports


Toggle filters

391 – 400 of 27411 results

Status is adjusted based on your filters.


CVE-2026-46727

Medium priority
Needs evaluation

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS...

7 affected packages

ruby2.3, ruby2.5, ruby2.7, ruby3.0, ruby3.2...

Package 26.04 LTS
ruby2.3 Not in release
ruby2.5 Not in release
ruby2.7 Not in release
ruby3.0 Not in release
ruby3.2 Not in release
ruby3.3 Needs evaluation
jruby Needs evaluation
Show all 7 packages Show less packages

CVE-2026-42627

Medium priority

Not in release

In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite model file to bypass buffer size validation and trigger a heap-based buffer over-read during model...

1 affected package

armnn

Package 26.04 LTS
armnn Not in release
Show less packages

CVE-2026-42506

Medium priority

Not in release

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

1 affected package

golang-golang-x-net-dev

Package 26.04 LTS
golang-golang-x-net-dev Not in release
Show less packages

CVE-2026-42502

Medium priority

Not in release

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

1 affected package

golang-golang-x-net-dev

Package 26.04 LTS
golang-golang-x-net-dev Not in release
Show less packages

CVE-2026-39821

Medium priority

Not in release

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This...

1 affected package

golang-golang-x-net-dev

Package 26.04 LTS
golang-golang-x-net-dev Not in release
Show less packages

CVE-2026-27136

Medium priority

Not in release

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

1 affected package

golang-golang-x-net-dev

Package 26.04 LTS
golang-golang-x-net-dev Not in release
Show less packages

CVE-2026-25681

Medium priority

Not in release

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

1 affected package

golang-golang-x-net-dev

Package 26.04 LTS
golang-golang-x-net-dev Not in release
Show less packages

CVE-2026-25680

Medium priority

Not in release

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

1 affected package

golang-golang-x-net-dev

Package 26.04 LTS
golang-golang-x-net-dev Not in release
Show less packages

CVE-2026-9256

Medium priority
Needs evaluation

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression...

1 affected package

nginx

Package 26.04 LTS
nginx Needs evaluation
Show less packages

CVE-2026-9277

Medium priority
Needs evaluation

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match...

1 affected package

node-shell-quote

Package 26.04 LTS
node-shell-quote Needs evaluation
Show less packages