VulnSea

enterprise_linux_appstream_eus_v_9_4 vulnerabilities

CVEs whose affected-version data names the enterprise_linux_appstream_eus_v_9_4 package (go, pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-35536Medium· 5.4
5mo ago

tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments (CVE-2026-35536)

A flaw was found in Tornado. A remote attacker could exploit this vulnerability by injecting specially crafted characters into the `domain`, `path`, and `samesite` arguments when setting cookies. This could lead to cookie attribute injecti…

SunlitRed Hat · Red Hat OpenShift AI 2.25EPSS 0.24%via CSAF
CVE-2026-27135High· 7.5
6mo ago

nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135)

A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 fram…

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.78%via CSAF
CVE-2025-47913High· 7.5
10mo ago

golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913)

A flaw in golang.org/x/crypto/ssh/agent causes the SSH agent client to panic when a peer responds with the generic SSH_AGENT_SUCCESS (0x06) message to requests expecting typed replies (e.g., List, Sign). The unmarshal layer produces an une…

TwilightRed Hat · Red Hat Enterprise Linux AppStream E4S (v.8.6)EPSS 0.62%via CSAF
CVE-2025-8194High· 7.5
1y ago

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and dea…

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via NVD
CVE-2023-0286High· 7.4
3y ago

openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)

A type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability ma…

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 60%via CSAF
enterprise_linux_appstream_eus_v_9_4 vulnerabilities (CVEs) · VulnSea