Search CVE reports


Toggle filters

831 – 840 of 38299 results

Status is adjusted based on your filters.


CVE-2026-23941

Medium priority
Needs evaluation

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program...

1 affected package

erlang

Package 20.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-32597

Medium priority
Fixed

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 ยง4.1.11. When a JWS token contains a crit array listing extensions that PyJWT...

1 affected package

pyjwt

Package 20.04 LTS
pyjwt Fixed
Show less packages

CVE-2026-32274

Medium priority
Needs evaluation

Black is the uncompromising Python code formatter. Prior to 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename...

1 affected package

black

Package 20.04 LTS
black Needs evaluation
Show less packages

CVE-2026-32259

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, when a memory allocation fails in the sixel encoder it would be possible to write past the end of a...

1 affected package

imagemagick

Package 20.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-32249

Medium priority
Not affected

Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]),...

1 affected package

vim

Package 20.04 LTS
vim Not affected
Show less packages

CVE-2026-32240

Medium priority
Needs evaluation

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be truncated to a 64-bit integer. In...

1 affected package

capnproto

Package 20.04 LTS
capnproto Needs evaluation
Show less packages

CVE-2026-32239

Medium priority
Needs evaluation

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead. In theory, this bug could...

1 affected package

capnproto

Package 20.04 LTS
capnproto Needs evaluation
Show less packages

CVE-2025-70873

Medium priority
Not affected

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

2 affected packages

sqlite, sqlite3

Package 20.04 LTS
sqlite Not affected
sqlite3 Not affected
Show less packages

CVE-2026-32141

Medium priority
Needs evaluation

flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential...

1 affected package

node-flatted

Package 20.04 LTS
node-flatted Needs evaluation
Show less packages

CVE-2026-32116

Medium priority
Needs evaluation

Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a file (wormhole receive) from a malicious party could result in overwriting...

1 affected package

magic-wormhole

Package 20.04 LTS
magic-wormhole Needs evaluation
Show less packages