VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3138 CVEsRSS

CVE-2026-18922Critical· 9.8
3w ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated s…

▾ MidnightRed Hat · redhat-ds:11EPSS 0.56%via NVD
CVE-2026-18453High· 7.5
3w ago

A flaw was found in 389 Directory Server

A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests …

▾ TwilightRed Hat · redhat-ds:11EPSS 0.85%via NVD
CVE-2026-86423Low· 3.3
3w ago

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can trigger the use-after-free, resulting in a crash (denial of…

▾ Sunlitimagemagick · imagemagickEPSS 0.11%via NVD
CVE-2026-86421Low· 3.7
3w ago

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service.

▾ Sunlitimagemagick · imagemagickEPSS 0.45%via NVD
CVE-2026-79678High· 8.1
3w ago

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated…

▾ TwilightRed Hat · ipaEPSS 0.66%via NVD
CVE-2026-76578Critical· 9.8PoC
3w ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a r…

▾ AbyssalRed Hat · ipaEPSS 0.96%via NVD
CVE-2026-19204High· 8.7
3w ago

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enab…

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This occurs when auto-fragmentation is enab…

▾ TwilightEclipse Foundation · Eclipse JettyEPSS 0.31%via NVD
CVE-2026-86289Medium· 4.3PoC
3w ago

A vulnerability was found in Ollama up to 0.31.1

A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible t…

▾ TwilightRed Hat · OllamaEPSS 0.69%via NVD
CVE-2026-84256High· 7.7
3w ago

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject

▾ TwilightOpenVPN · OpenVPNEPSS 0.38%via NVD
CVE-2026-84226High· 8.5
3w ago

OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps

OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps

▾ TwilightOpenVPN · OpenVPNEPSS 0.14%via NVD
CVE-2026-82312Low· 1.8⚖ disputed
3w ago

OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects

OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects

▾ SunlitOpenVPN · OpenVPNEPSS 0.10%via NVD
CVE-2026-81830Medium· 5.6
3w ago

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

▾ SunlitOpenVPN · OpenVPNEPSS 0.15%via NVD
CVE-2026-81738Low· 2.3
3w ago

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

▾ SunlitOpenVPN · OpenVPNEPSS 0.33%via NVD
CVE-2026-78254High· 7.4
3w ago

The ftp and scp tasks of Apache Ant can download files from a remote server

The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite…

▾ Twilightapache · antEPSS 0.52%via NVD
CVE-2026-78221Medium· 5.9
3w ago

An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.

An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.

▾ SunlitOpenVPN · OpenVPNEPSS 0.12%via NVD
CVE-2026-78043Medium· 5.6
3w ago

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths

▾ SunlitOpenVPN · OpenVPNEPSS 0.17%via NVD
CVE-2026-86315Medium· 6.2
3w ago

An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definiti…

An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definiti…

▾ SunlitSamsung Opensource · EscargotEPSS 0.17%via NVD
CVE-2026-82209High· 8.2PoC⚖ disputed
3w ago

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Do…

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Do…

▾ Midnighthaxx · curlEPSS 0.37%via NVD
CVE-2026-82208High· 7.5PoC⚖ disputed
3w ago

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the cached sto…

▾ Midnighthaxx · curlEPSS 0.41%via NVD
CVE-2026-80231High· 7.5PoC⚖ disputed
3w ago

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.

▾ Midnighthaxx · curlEPSS 0.90%via NVD
CVE-2026-80230High· 7.5PoC⚖ disputed
3w ago

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections establishe…

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections establishe…

▾ Midnighthaxx · curlEPSS 0.37%via NVD
CVE-2026-19931Critical· 9.8PoC⚖ disputed
3w ago

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previo…

▾ Abyssalhaxx · curlEPSS 0.75%via NVD
CVE-2026-18924Critical· 9.1PoC⚖ disputed
3w ago

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

▾ Abyssalhaxx · curlEPSS 0.58%via NVD
CVE-2026-13608High· 7.4PoC⚖ disputed
3w ago

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a …

▾ Midnighthaxx · curlEPSS 0.48%via NVD
CVE-2026-83534Medium· 6.4
3w ago

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and late…

▾ SunlitDALIBO · PostgreSQL AnonymizerEPSS 0.19%via NVD
CVE-2026-19634Medium· 6.4
3w ago

PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions

PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() o…

▾ SunlitDALIBO · PostgreSQL AnonymizerEPSS 0.18%via NVD
CVE-2026-19633High· 8.8
3w ago

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in t…

▾ TwilightDALIBO · PostgreSQL AnonymizerEPSS 0.42%via NVD
CVE-2026-86253Medium· 5.9
3w ago

h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic()

h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-encoded dot segments (%2e%2e) are passed to decodeURI() and decode…

▾ Sunlith3js · h3EPSS 0.62%via NVD
CVE-2026-86252Medium· 5.3PoC
3w ago

h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns

h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type di…

▾ Twilighth3js · h3EPSS 0.36%via NVD
CVE-2026-86251Medium· 5.9PoC
3w ago

h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility

h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequences (e.g. %252e%252e) to be decoded to %2e%2e, which survives r…

▾ Twilighth3js · h3EPSS 0.43%via NVD
CVEs tagged “csaf” — page 54 · VulnSea