VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3093 CVEsRSS

CVE-2026-79312Medium· 6.8
5d ago

webpy web.py 0.76 is vulnerable to Session Fixation

webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, and _save() writes back under the same session_id; no rotation af…

▾ SunlitRed HatEPSS 0.29%via NVD
CVE-2026-79313Critical· 9.8⚖ disputed
5d ago

webpy web.py 0.76 is vulnerable to Insufficient Session Expiration

webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an exp…

▾ MidnightRed HatEPSS 0.38%via NVD
CVE-2026-95619High· 7.7
5d ago

A flaw was found in libstdc++

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corrup…

▾ TwilightRed Hat · gcc-mainEPSS 0.36%via NVD
CVE-2026-63275Medium· 5.4
5d ago

LibreOffice can read CFF fonts, which may be embedded in documents

LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the arra…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-63276Medium· 5.4
5d ago

LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents

LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators we…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-63274Medium· 5.4
5d ago

LibreOffice Draw can import PDF documents

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually presen…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-95508High· 7.4
5d ago

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply bu…

▾ TwilightRed Hat · libslirpEPSS 0.57%via NVD
CVE-2016-15059Critical· 9.8
5d ago

Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized …

Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized …

▾ MidnightRed Hat · Net-IDN-EncodeEPSS 0.42%via NVD
CVE-2026-95503Medium· 6.8
5d ago

A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution

A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without SPNEGO, the system fails to verify the identity of the Key Di…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.19%via NVD
CVE-2026-94627High· 7.5
6d ago

vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments

vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhausti…

▾ Twilightvllm-project · vllmEPSS 0.63%via NVD
CVE-2026-94626High· 7.5
6d ago

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode…

▾ Twilightvllm-project · vllmEPSS 0.63%via NVD
CVE-2026-94625Medium· 5.3⚖ disputed
6d ago

vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed

vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender…

▾ Sunlitvllm-project · vllmEPSS 0.52%via NVD
CVE-2026-94624High· 7.5
6d ago

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port …

▾ Twilightvllm-project · vllmEPSS 0.63%via NVD
CVE-2026-94623High· 7.5
6d ago

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated dep…

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated dep…

▾ Twilightvllm-project · vllmEPSS 0.63%via NVD
CVE-2026-94622High· 7.5
6d ago

vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments

vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomplete kv_transfer_params dictionary entr…

▾ Twilightvllm-project · vllmEPSS 0.63%via NVD
CVE-2026-79079High· 7.8PoC
6d ago

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

▾ MidnightRed HatEPSS 0.19%via NVD
CVE-2026-73553High· 7.5PoC
6d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's router strips the semicolon suffix befo…

▾ Midnightenvoyproxy · envoyEPSS 0.52%via NVD
CVE-2026-93433Medium· 5.5
6d ago

A flaw was found in libstoragemgmt

A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System Interface) Vital Product Data (VPD) page 0x80 data. This malformed data, spec…

▾ SunlitRed Hat · libstoragemgmtEPSS 0.15%via NVD
CVE-2026-73512High· 7.5PoC
6d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream r…

▾ Midnightenvoyproxy · envoyEPSS 0.83%via NVD
CVE-2026-50572Medium· 5.9
6d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HTTP external-authorization client can retain a stale request callback after a request is reject…

▾ Sunlitenvoyproxy · envoyEPSS 0.68%via NVD
CVE-2026-49811High· 8.4
6d ago

Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability

Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to…

▾ TwilightDell · Command | Monitor (DCM)EPSS 0.14%via NVD
CVE-2026-73549Medium· 5.3
6d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address paths reconstruct scoped IPv6 addres…

▾ Sunlitenvoyproxy · envoyEPSS 0.60%via NVD
CVE-2026-48521Medium· 5.9PoC
6d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while selectin…

▾ Twilightenvoyproxy · envoyEPSS 0.70%via NVD
CVE-2026-92382Medium· 4.1
6d ago

An out-of-bounds write flaw was found in usbredir

An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() …

▾ SunlitRed Hat · usbredirEPSS 0.14%via NVD
CVE-2026-94449High· 7.5
6d ago

A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices

A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, …

▾ TwilightRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.49%via NVD
CVE-2026-53940High· 8.8PoC
6d ago

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior to 26.5.2, parse_entry_point_def in conda/common/path/python.py accepted an unvalidated entry-point command from a n…

▾ Midnightconda · condaEPSS 0.55%via NVD
CVE-2026-71543High· 7.2
6d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated…

▾ Twilightopenbao · github.com/openbao/openbaoEPSS 0.42%via NVD
CVE-2026-80110High· 8.1
6d ago

A flaw was found in pki-core

A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to ove…

▾ TwilightRed Hat · pki-coreEPSS 0.24%via NVD
CVE-2026-75939High· 7.4
6d ago

A flaw was found in openshift/oc-mirror

A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature v…

▾ TwilightRed Hat · openshift4/oc-mirror-plugin-rhel8EPSS 0.31%via NVD
CVE-2026-94184High· 8.1
6d ago

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixe…

▾ TwilightRed Hat · fetchmailEPSS 0.78%via NVD
CVEs tagged “csaf” — page 8 · VulnSea