Search CVE reports


Toggle filters

1 – 10 of 44354 results

Status is adjusted based on your filters.


CVE-2026-71554

Medium priority
Needs evaluation

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where...

1 affected package

python-h2

Package 20.04 LTS
python-h2 Needs evaluation
Show less packages

CVE-2026-71498

Medium priority
Needs evaluation

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end...

1 affected package

node-re2

Package 20.04 LTS
node-re2 Needs evaluation
Show less packages

CVE-2026-71497

Medium priority
Needs evaluation

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior...

1 affected package

jsoup

Package 20.04 LTS
jsoup Needs evaluation
Show less packages

CVE-2026-71488

Medium priority
Needs evaluation

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several...

2 affected packages

commonmark, markdown

Package 20.04 LTS
commonmark
markdown Needs evaluation
Show less packages

CVE-2026-71478

Medium priority
Needs evaluation

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab,...

2 affected packages

commonmark, markdown

Package 20.04 LTS
commonmark
markdown Needs evaluation
Show less packages

CVE-2026-71430

Medium priority
Needs evaluation

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty...

1 affected package

node-re2

Package 20.04 LTS
node-re2 Needs evaluation
Show less packages

CVE-2026-70632

Medium priority
Needs evaluation

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI...

2 affected packages

ffmpeg, libav

Package 20.04 LTS
ffmpeg Needs evaluation
libav
Show less packages

CVE-2026-70631

Medium priority
Needs evaluation

FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file...

2 affected packages

ffmpeg, libav

Package 20.04 LTS
ffmpeg Needs evaluation
libav
Show less packages

CVE-2026-70630

Medium priority
Needs evaluation

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory...

2 affected packages

ffmpeg, libav

Package 20.04 LTS
ffmpeg Needs evaluation
libav
Show less packages

CVE-2026-70629

Medium priority
Needs evaluation

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a...

2 affected packages

ffmpeg, libav

Package 20.04 LTS
ffmpeg Needs evaluation
libav
Show less packages