VulnSea

CWE-1286

CVEs classified under CWE-1286, newest first.

18 CVEsRSS

CVE-2026-87080None
today

Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the…

Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the…

Sunlitvia NVD
CVE-2026-87082None
today

Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag set ov…

Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag set ov…

Sunlitvia NVD
CVE-2026-69211Medium· 4.8
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-influenced name, content, domain, path, and extension values without neutralizing semicolons or control characters. An a…

Sunlithttp4s · http4sEPSS 0.22%via NVD
CVE-2026-88260High· 8.7
1w ago

Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OA…

Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OA…

TwilightBrainzcompany · Zenius EMS 8.0EPSS 0.20%via NVD
CVE-2026-88009High· 8.2
1w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empty. The rewriteRequestBuilder path eval…

Twilighttraefik · traefikEPSS 0.27%via NVD
CVE-2026-83611Medium
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMParser.parseFromString() can silent…

Sunlitxmldom · @xmldom/xmldomEPSS 0.35%via NVD
CVE-2026-72916None
1mo ago

Mastodon is a free, open-source social network server based on ActivityPub

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.private_address? in app/lib/private_address_check.rb normalized IPv4-mapped IPv6 addresses …

SunlitEPSS 0.36%via NVD
CVE-2026-50131High· 8.6PoC
2mo ago

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

Midnightfedify · @fedify/fedifyEPSS 0.35%via GHSA
CVE-2026-55767Medium· 5.8
3mo ago

guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts

guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts

Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.21%via GHSA
CVE-2026-48059High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when…

Twilightnetty · nettyEPSS 0.63%via NVD
CVE-2026-42579High· 7.5PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirec…

Midnightnetty · nettyEPSS 1.0%via NVD
CVE-2026-41293High· 7.3PoC⚖ disputed
4mo ago

tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293)

Apache Tomcat did not validate HTTP/2 request headers, triggering unexpected application behavior, as applications may presume that header values exposed through the Servlet API would be valid.

MidnightRed Hat · Red Hat Enterprise Linux AppStream EUS (v. 10.0)EPSS 1.7%via CSAF
CVE-2026-44244High· 7.3
4mo ago

GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration (CVE-2026-44244)

A flaw was found in GitPython, a Python library used to interact with Git repositories. The `GitConfigParser.set_value()` function does not properly validate input for newlines. This vulnerability allows an attacker to inject malicious con…

TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.24%via CSAF
CVE-2026-40890High· 7.5
5mo ago

github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input (CVE-2026-40890)

A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input cont…

TwilightRed Hat · Multicluster Global Hub 1.4.9EPSS 0.35%via CSAF
CVE-2026-33218High· 7.5
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed mess…

Twilightlinuxfoundation · nats-serverEPSS 0.62%via NVD
CVE-2026-27889High· 7.5PoC
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic…

Midnightlinuxfoundation · nats-serverEPSS 0.58%via NVD
CVE-2026-25679High· 7.5
6mo ago

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

Twilightgolang · goEPSS 0.73%via NVD
CVE-2025-13878High· 7.5
8mo ago

Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through …

Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through …

TwilightEPSS 9.2%via NVD
CWE-1286 vulnerabilities (CVEs) · VulnSea