VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3138 CVEsRSS

CVE-2026-18798High· 7.5
1mo ago

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server pr…

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server pr…

▾ Twilightopenssl · opensslEPSS 1.5%via NVD
CVE-2026-68569High· 8.1
1mo ago

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tom…

▾ Twilightapache · tomcatEPSS 0.60%via NVD
CVE-2026-79049High· 7.1⚖ disputed
1mo ago

chromium-browser: chromium-browser: Incorrect reference resolution in Passwords (CVE-2026-79049)

An incorrect reference resolution flaw was found in the Passwords component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=513786555

▾ TwilightRed Hat · ChromeEPSS 0.26%via CSAF
CVE-2026-79050Medium· 5.4
1mo ago

chromium-browser: Google Chrome: System access restriction bypass via crafted HTML page (CVE-2026-79050)

A flaw was found in Google Chrome's Network component. This incorrect authorization vulnerability allows a remote attacker to bypass system access restrictions. The attacker can achieve this by enticing a user to open a specially crafted H…

▾ SunlitRed Hat · ChromeEPSS 0.24%via CSAF
CVE-2026-79006Medium· 4.3
1mo ago

chromium-browser: Google Chrome: Web origin policy bypass via crafted network traffic (CVE-2026-79006)

A flaw was found in Google Chrome. This vulnerability, located in the HttpsUpgrades component, allows a remote attacker to bypass the web origin policy. By sending specially crafted network traffic, an attacker could circumvent security re…

▾ SunlitRed Hat · ChromeEPSS 0.25%via CSAF
CVE-2026-79136Medium· 5.4
1mo ago

chromium-browser: Chromium: Web origin policy bypass via incorrect ServiceWorker authorization (CVE-2026-79136)

A flaw was found in Chromium. This incorrect authorization vulnerability in the ServiceWorker component allows a remote attacker to bypass the web origin policy. By crafting a malicious HTML page, an attacker can circumvent security restri…

▾ SunlitRed Hat · ChromeEPSS 0.27%via CSAF
CVE-2026-79143Medium· 4.3
1mo ago

chromium-browser: Google Chrome FileSystem: System access bypass through crafted HTML and social engineering (CVE-2026-79143)

A flaw was found in Google Chrome's FileSystem component. This incorrect authorization vulnerability allows a remote attacker to bypass system access restrictions. By leveraging social engineering techniques with a specially crafted HTML p…

▾ SunlitRed Hat · ChromeEPSS 0.24%via CSAF
CVE-2026-79199Medium· 4.3
1mo ago

chromium-browser: Chromium-browser: System access restriction bypass via crafted HTML page (CVE-2026-79199)

A flaw was found in chromium-browser. This incorrect authorization vulnerability allows a remote attacker to bypass system access restrictions. By crafting a malicious HTML page, an attacker can gain unauthorized access within the network …

▾ SunlitRed Hat · ChromeEPSS 0.24%via CSAF
CVE-2026-79151Medium· 6.5⚖ disputed
1mo ago

chromium-browser: Chromium-browser Safebrowsing: Bypass system access restrictions via improper input validation. (CVE-2026-79151)

A flaw was found in Chromium-browser's Safebrowsing component. A remote attacker could exploit this vulnerability by providing a specially crafted file. This could allow the attacker to bypass system access restrictions.

▾ SunlitRed Hat · ChromeEPSS 0.23%via CSAF
CVE-2026-79251Medium· 6.5⚖ disputed
1mo ago

chromium-browser: Google Chrome: Web origin policy bypass via improper input validation (CVE-2026-79251)

A flaw was found in Google Chrome. Improper input validation in the Network component allows a remote attacker to potentially bypass the web origin policy. This can be achieved by enticing a user to visit a specially crafted HTML page. The…

▾ SunlitRed Hat · ChromeEPSS 0.28%via CSAF
CVE-2026-79217Medium· 5.4
1mo ago

chromium-browser: chromium-browser: Incorrect authorization in Mobile (CVE-2026-79217)

An incorrect authorization flaw was found in the Mobile component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=514055709

▾ SunlitRed Hat · ChromeEPSS 0.24%via CSAF
CVE-2026-79020Medium· 4.3⚖ disputed
1mo ago

chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-79020)

An out of bounds read flaw was found in the Skia component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=514017820

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.37%via CSAF
CVE-2026-79099Medium· 6.5
1mo ago

chromium-browser: Google Chrome: System access restriction bypass via crafted HTML page (CVE-2026-79099)

A flaw was found in Google Chrome's Network component. A remote attacker could exploit this vulnerability by enticing a user to visit a specially crafted HTML page. This could allow the attacker to bypass system access restrictions, leadin…

▾ SunlitRed Hat · ChromeEPSS 0.29%via CSAF
CVE-2026-79173Medium· 4.3
1mo ago

chromium-browser: Chromium-browser: UI spoofing via crafted HTML page (CVE-2026-79173)

A flaw was found in chromium-browser. A remote attacker could exploit this vulnerability by crafting a malicious HTML page, leading to user interface (UI) misrepresentation. This misrepresentation allows the attacker to spoof UI elements, …

▾ SunlitRed Hat · ChromeEPSS 0.26%via CSAF
CVE-2026-79191High· 7.6⚖ disputed
1mo ago

chromium-browser: chromium-browser: Incorrect authorization in SiteIsolation (CVE-2026-79191)

An incorrect authorization flaw was found in the SiteIsolation component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=517606780

▾ TwilightRed Hat · ChromeEPSS 0.23%via CSAF
CVE-2026-79229Medium· 6.8
1mo ago

chromium-browser: angle: Chromium: Information disclosure via uninitialized resource in ANGLE (CVE-2026-79229)

A flaw was found in ANGLE, a component within Chromium. This uninitialized resource vulnerability could allow a remote attacker, who has already compromised the renderer process, to read sensitive memory outside of the security sandbox. Th…

▾ SunlitRed Hat · Red Hat Enterprise Linux 7EPSS 0.35%via CSAF
CVE-2026-79221Medium· 6.5
1mo ago

chromium-browser: chromium-browser: Uninitialized resource in Dawn (CVE-2026-79221)

An uninitialized resource flaw was found in the Dawn component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=532923954

▾ SunlitRed Hat · ChromeEPSS 0.35%via CSAF
CVE-2026-79270High· 7.4
1mo ago

chromium-browser: angle: Chromium-browser: Memory disclosure via uninitialized resource in ANGLE (CVE-2026-79270)

A flaw was found in chromium-browser. A remote attacker could exploit an uninitialized resource vulnerability in ANGLE by crafting a malicious HTML page. This could allow the attacker to read sensitive memory outside of the browser's secur…

▾ TwilightRed Hat · Red Hat Enterprise Linux 7EPSS 0.35%via CSAF
CVE-2026-79042Medium· 5.4
1mo ago

chromium-browser: Google Chrome: Missing authorization in Payments allows system access restriction bypass (CVE-2026-79042)

A flaw was found in Google Chrome on Android. Missing authorization in the Payments functionality allows a remote attacker, leveraging social engineering, to potentially bypass system access restrictions. This can be achieved by enticing a…

▾ SunlitRed Hat · ChromeEPSS 0.24%via CSAF
CVE-2026-79652Medium· 5.9
1mo ago

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access token…

▾ SunlitRed Hat · keycloak-rhel9-containerEPSS 0.34%via NVD
CVE-2026-79776Medium· 5.3PoC⚖ disputed
1mo ago

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full p…

▾ Twilightrclone · rcloneEPSS 0.43%via NVD
CVE-2026-14457High· 7.5
1mo ago

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solic…

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solic…

▾ Twilightopenssl · opensslEPSS 1.0%via NVD
CVE-2026-63072High· 7.5PoC
1mo ago

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-b…

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-b…

▾ Midnightopenssl · opensslEPSS 1.0%via NVD
CVE-2026-63076High· 7.5
1mo ago

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a d…

▾ Twilightopenssl · opensslEPSS 1.8%via NVD
CVE-2026-75803Critical· 9.1⚖ disputed
1mo ago

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: …

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: …

▾ Midnightopenssl · opensslEPSS 0.22%via NVD
CVE-2026-63075High· 7.5
1mo ago

Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection.…

Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection.…

▾ Twilightopenssl · opensslEPSS 0.78%via NVD
CVE-2026-63074Medium· 5.9
1mo ago

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid)

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequentl…

▾ Sunlitopenssl · opensslEPSS 0.56%via NVD
CVE-2026-63073Critical· 9.8⚖ disputed
1mo ago

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client t…

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client t…

▾ Midnightopenssl · opensslEPSS 1.2%via NVD
CVE-2026-54874High· 7.5
1mo ago

Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to mak…

Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to mak…

▾ Twilightopenssl · opensslEPSS 1.3%via NVD
CVE-2026-68515High· 7.1
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.19%via NVD
CVEs tagged “csaf” — page 61 · VulnSea