Search CVE reports


Toggle filters

181 – 190 of 53685 results

Status is adjusted based on your filters.


CVE-2026-85532

Medium priority
Needs evaluation

Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages....

1 affected package

wss4j

Package 22.04 LTS
wss4j Needs evaluation
Show less packages

CVE-2026-79768

Medium priority
Needs evaluation

Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd...

1 affected package

apache2

Package 22.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-77387

Medium priority
Needs evaluation

geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string...

1 affected package

geopy

Package 22.04 LTS
geopy Needs evaluation
Show less packages

CVE-2026-73857

Medium priority
Needs evaluation

[GHSA-jx3r-phvx-2jmj: XML request body processor dereferences an uninitialized parser context pointer]

1 affected package

modsecurity

Package 22.04 LTS
modsecurity Needs evaluation
Show less packages

CVE-2026-73856

Medium priority
Needs evaluation

[GHSA-vmg8-j66p-vgvw: Response body inspection bypass via non-canonical Content-Type casing]

1 affected package

modsecurity

Package 22.04 LTS
modsecurity Needs evaluation
Show less packages

CVE-2026-73637

Medium priority
Needs evaluation

Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent...

1 affected package

apache2

Package 22.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-73636

Medium priority
Needs evaluation

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via...

1 affected package

apache2

Package 22.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-68496

Medium priority
Needs evaluation

The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this...

1 affected package

jackson-dataformat-smile

Package 22.04 LTS
jackson-dataformat-smile Needs evaluation
Show less packages

CVE-2026-68495

Medium priority
Needs evaluation

The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this...

1 affected package

jackson-dataformat-cbor

Package 22.04 LTS
jackson-dataformat-cbor Needs evaluation
Show less packages

CVE-2026-63718

Medium priority
Needs evaluation

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects...

1 affected package

apache2

Package 22.04 LTS
apache2 Needs evaluation
Show less packages