VulnSea

CWE-390

CVEs classified under CWE-390, newest first.

9 CVEsRSS

CVE-2026-85716Low· 3.7
5d ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM…

SunlitAsyncHttpClient · async-http-clientEPSS 0.32%via NVD
CVE-2026-29810Medium· 4.3
1w ago

CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.

CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.

SunlitCyberPanel · CyberPanelEPSS 0.30%via NVD
CVE-2026-89499Medium· 5.5⚖ disputed
1w ago

kernel: ring-buffer: Stop remote reader update when page swap fails (CVE-2026-89499)

A flaw was found in the Linux kernel's ring-buffer component. When a remote reader update fails during a page swap, the system incorrectly proceeds as if the swap succeeded. This can lead to log flooding, potentially causing a denial of se…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.12%via CSAF
CVE-2026-85014Medium· 5.9
2w ago

undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake

undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean close the internal socket-close handler calls abort on the wri…

Sunlitnodejs · undiciEPSS 0.37%via NVD
CVE-2026-59643High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.

Twilightbouncycastle · bc-javaEPSS 0.16%via NVD
CVE-2026-53434Critical· 9.1
2mo ago

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 th…

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 th…

Midnightapache · tomcatEPSS 0.59%via NVD
CVE-2026-52989Critical· 9.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currently, when nvmet_tcp_build_pdu_iovec() detects an out-of-bounds PDU length or offset, it tr…

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currently, when nvmet_tcp_build_pdu_iovec() detects an out-of-bounds PDU length or offset, it tr…

MidnightEPSS 0.36%via NVD
CVE-2025-26465Medium· 6.8PoC
1y ago

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error …

Twilightopenbsd · opensshEPSS 7.7%via NVD
CVE-2024-12086Medium· 6.1
1y ago

A flaw was found in rsync

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server w…

Sunlitsamba · rsyncEPSS 1.8%via NVD
CWE-390 vulnerabilities (CVEs) · VulnSea