VulnSea

CWE-400

CVEs classified under CWE-400, newest first.

623 CVEsRSS

CVE-2026-10668Low· 2.4
2mo ago

The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage unconditionally (base->CEPTXCNT = len in numaker_hsusbd_ep_trigger)

The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage unconditionally (base->CEPTXCNT = len in numaker_hsusbd_ep_trigger). Because the HSUSBD hardware cannot disarm a cont…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-59161High· 7.5
2mo ago

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows and GetRows does not enforce the TotalRows limit on the row r attribute, allowing a smal…

▾ Twilightexcelize · excelizeEPSS 0.66%via NVD
CVE-2026-55781NonePoC
2mo ago

NanaZip is the 7-Zip derivative intended for the modern Windows experience

NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler in NanaZip.Codecs.Archive.Ufs.cpp validates the superblock block size only against the MINBSIZE lower bo…

▾ TwilightEPSS 0.16%via NVD
GHSA-9mqm-qcwf-5qhgMedium· 5.5
2mo ago

CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources

CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources

▾ Sunlitcredsweeper · credsweepervia GHSA
CVE-2026-49866High· 7.5
2mo ago

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

▾ Twilightlibp2p · @libp2p/gossipsubEPSS 0.63%via GHSA
CVE-2026-49851High· 7.5
2mo ago

Mistune: Potential DoS via quadratic-time parsing in parse_link_text

Mistune: Potential DoS via quadratic-time parsing in parse_link_text

▾ Twilightmistune · mistuneEPSS 0.63%via OSV
GHSA-52vm-mxx8-f227High· 7.7
2mo ago

Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths

Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths

▾ Twilightphantom-audio · phantom-audiovia GHSA
CVE-2026-49476High· 7.5
2mo ago

Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists

Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists

▾ Twilightsoupsieve · soupsieveEPSS 0.64%via OSV
CVE-2026-49485High· 7.5
2mo ago

org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

▾ Twilightuhn · ca.uhn.hapi.fhir:org.hl7.fhir.dstu2EPSS 0.68%via GHSA
CVE-2026-59879Medium· 5.3⚖ disputed
2mo ago

immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations (CVE-2026-59879)

A flaw was found in Immutable.js, a library providing persistent immutable data structures. This vulnerability occurs when specific List operations, such as List#set or List#setSize, are provided with an index or size value within a partic…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.66%via CSAF
CVE-2026-58210High· 7.5
2mo ago

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated MQTT client could cause the server to retain large incomplete MQTT CONNECT packets before a…

▾ Twilightlinuxfoundation · nats-serverEPSS 0.74%via NVD
CVE-2026-9165High· 7.7
2mo ago

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS)

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply neste…

▾ TwilightRed Hat · advanced-cluster-security/rhacs-main-rhel8EPSS 0.55%via NVD
CVE-2026-35358Medium· 4.4
2mo ago

cp: -R reads device nodes as streams, destroying device semantics

cp: -R reads device nodes as streams, destroying device semantics

▾ Sunlituu_cp · uu_cpEPSS 0.18%via GHSA
CVE-2026-35365Medium· 6.6
2mo ago

mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)

mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)

▾ Sunlituu_mv · uu_mvEPSS 0.19%via GHSA
CVE-2026-26307None
2mo ago

Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.

Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.

▾ SunlitEPSS 0.63%via NVD
CVE-2026-50196High· 7.5
2mo ago

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

▾ TwilightSteeltoe · Steeltoe.Discovery.EurekaEPSS 0.61%via GHSA
CVE-2026-45822High· 7.5
2mo ago

decode-uri-component: decode-uri-component: Denial of Service via crafted input (CVE-2026-45822)

A flaw was found in the `decode-uri-component` library. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by submitting specially crafted input. The `decode()` function, when processing a large number of enco…

▾ TwilightRed Hat · Red Hat Quay 3.12EPSS 0.51%via CSAF
CVE-2026-13149High· 7.5
2mo ago

brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)

A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time c…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.36%via CSAF
CVE-2026-57081High· 7.5
2mo ago

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining…

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-57080High· 7.5
2mo ago

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framing in _process_messages trusts the 4-byte length prefix sent by a connected peer with no …

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framing in _process_messages trusts the 4-byte length prefix sent by a connected peer with no …

▾ TwilightEPSS 0.49%via NVD
CVE-2026-48593Medium
2mo ago

oban_web: Unbounded range expansion in cron describe causes memory exhaustion

oban_web: Unbounded range expansion in cron describe causes memory exhaustion

▾ Sunlitoban_web · oban_webEPSS 0.47%via GHSA
CVE-2023-46118Medium· 4.9
2mo ago

RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API

RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API

▾ Sunlitrabbit_common · rabbit_commonEPSS 1.1%via GHSA
CVE-2026-47214High· 7.1
3mo ago

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.

▾ Twilightdocling · doclingEPSS 0.37%via NVD
CVE-2026-47077High
3mo ago

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

▾ Twilighthackney · hackneyEPSS 0.70%via GHSA
CVE-2026-48990Medium· 5.3
3mo ago

joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization

joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization

▾ Sunlitjoserfc · joserfcEPSS 0.27%via OSV
CVE-2026-47071High
3mo ago

Hackney: `ssl:connect/2` post-handshake upgrade has no timeout

Hackney: `ssl:connect/2` post-handshake upgrade has no timeout

▾ Twilighthackney · hackneyEPSS 0.70%via GHSA
CVE-2026-47074High
3mo ago

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

▾ Twilighthackney · hackneyEPSS 0.38%via GHSA
CVE-2026-47073High
3mo ago

Hackney has unbounded buffer accumulation in WebSocket

Hackney has unbounded buffer accumulation in WebSocket

▾ Twilighthackney · hackneyEPSS 0.82%via GHSA
CVE-2026-49293High· 7.5
3mo ago

js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals

js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals

▾ Twilightjs-toml · js-tomlEPSS 0.64%via GHSA
GHSA-pvrg-q6jw-42p7High· 7.5
3mo ago

Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service

Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service

▾ Twilighttraefik · github.com/traefik/traefikvia GHSA
CWE-400 vulnerabilities (CVEs) — page 15 · VulnSea