VulnSea

CWE-248

CVEs classified under CWE-248, newest first.

80 CVEsRSS

CVE-2026-61799Medium· 5.3
1mo ago

netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

Sunlitnetty · io.netty.incubator:netty-incubator-codec-bhttpvia GHSA
CVE-2026-52738Medium
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a long chain of transparent self-spends to one address can permanently halt Zebra nodes. In zebra-state/src/service/finalized_state/zebra_…

Sunlitzebra-state · zebra-stateEPSS 0.37%via NVD
CVE-2026-52739Medium· 5.9
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placing the same shielded transaction in a non-finalized parent block and its child. In zebra-state/src/service/non_finali…

Sunlitzebra-state · zebra-stateEPSS 0.39%via NVD
CVE-2026-52731Medium· 6.5
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by supplying a getblocktemplate LongPollId containing multi-byte UTF-8 characters. In zebra-r…

Sunlitzebra-rpc · zebra-rpcEPSS 0.38%via NVD
CVE-2026-61666High· 7.5
1mo ago

websocket-driver is a WebSocket protocol handler with pluggable I/O

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing …

Twilightwebsocket-driver · websocket-driverEPSS 0.34%via NVD
CVE-2026-73418High· 7.5
1mo ago

NextAuth.js provides authentication for Next.js

NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it r…

TwilightEPSS 0.46%via NVD
GHSA-pfvm-w89x-94jwHigh· 7.5
1mo ago

SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)

SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)

TwilightSIPSorcery · SIPSorceryvia GHSA
CVE-2026-73088High· 7.5
1mo ago

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist()…

TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.44%via NVD
CVE-2026-62909High· 7.8
1mo ago

.NET Elevation of Privilege Vulnerability

Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · .NET 10.0EPSS 0.29%via CVEORG
GHSA-3x6r-wxxg-53vvMedium· 5.3
1mo ago

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic

Sunlitrclone · github.com/rclone/rclonevia GHSA
CVE-2026-13697High· 7.4
1mo ago

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

Twilightundici · undiciEPSS 0.46%via GHSA
CVE-2026-52856High· 7.5
1mo ago

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

Twilightpterodactyl · github.com/pterodactyl/wingsEPSS 0.34%via NVD
CVE-2026-65834Medium· 6.8
1mo ago

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests

Sunlitprojectcapsule · github.com/projectcapsule/capsuleEPSS 0.27%via GHSA
GHSA-wqjv-9729-c5q2Medium· 5.3
1mo ago

SvelteKit: Big remote form function payloads can cause Node process to crash

SvelteKit: Big remote form function payloads can cause Node process to crash

Sunlitsveltejs · @sveltejs/kitvia GHSA
GHSA-hrxh-6v49-42gfHigh
2mo ago

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

Twilightgrpc · google.golang.org/grpcvia GHSA
CVE-2026-59892High· 7.5
2mo ago

OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header

OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header

Twilightopentelemetry · @opentelemetry/propagator-jaegerEPSS 0.78%via GHSA
CVE-2026-64612High· 7.5
2mo ago

A flaw was found in libcupsfilters and cups-filters

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file…

TwilightEPSS 0.38%via NVD
CVE-2026-59875Medium· 5.3
2mo ago

node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

Sunlittar · tarEPSS 0.51%via GHSA
CVE-2025-71391None
2mo ago

SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database

SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated users to crash the database. Attackers can send crafted HTTP queries containing null bytes to the /sql endpoint, caus…

SunlitEPSS 0.30%via NVD
CVE-2024-58369Medium· 6.5
2mo ago

SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic

SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the Su…

SunlitEPSS 0.45%via NVD
CVE-2024-58368High· 7.5
2mo ago

SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters

SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenticated attackers can send crafted HTTP requests with malformed header values to trigger a…

TwilightEPSS 0.65%via NVD
CVE-2024-58365Medium· 6.5
2mo ago

SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions

SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. Authorized clients can craft pre-parsed queries invoking nonexistent functions to …

SunlitEPSS 0.45%via NVD
CVE-2024-58364Medium· 6.5
2mo ago

SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters

SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. Authorized clients can submit malformed queries that trigger a panic i…

SunlitEPSS 0.45%via NVD
CVE-2024-58361Medium· 6.5
2mo ago

SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings

SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. Authorized clients can execute malformed queries with empty string conversions to reco…

SunlitEPSS 0.45%via NVD
CVE-2024-58359Medium· 6.5
2mo ago

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clients can execute queries with ORDER BY rand() to trigger a panic in the sorting function,…

SunlitEPSS 0.45%via NVD
CVE-2024-58358Medium· 4.9
2mo ago

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles

SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user ass…

SunlitEPSS 0.47%via NVD
CVE-2024-58357Medium· 6.5
2mo ago

SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_opt

SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_opt. Authorized clients can repeatedly invoke rand::time() to reli…

SunlitEPSS 0.45%via NVD
CVE-2026-50328High· 7.5
2mo ago

Windows Server Update Service (WSUS) Tampering Vulnerability

Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 1.2%via CVEORG
CVE-2026-59162High· 7.5
2mo ago

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks only the upper bound before indexing the shared string slice,…

Twilightexcelize · excelizeEPSS 0.39%via NVD
CVE-2026-27844Low· 2.7
2mo ago

Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denia…

Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denia…

Sunlitgallagher · command_centreEPSS 0.39%via NVD
CWE-248 vulnerabilities (CVEs) — page 2 · VulnSea