VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3138 CVEsRSS

CVE-2026-48864High· 7.8
4mo ago

A flaw was found in libsolv

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` …

▾ Twilightopensuse · libsolvEPSS 0.26%via NVD
CVE-2026-48710Medium· 6.5CISA KEVPoC
4mo ago

Starlette is a lightweight ASGI framework/toolkit

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `…

▾ Midnightstarlette · starletteEPSS 7.1%via NVD
CVE-2026-5260High· 8.2
4mo ago

A flaw was found in libgnutls

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corrupti…

▾ TwilightRed Hat · gnutlsEPSS 0.95%via NVD
CVE-2026-42502Medium· 6.1
4mo ago

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

▾ Sunlitx · golang.org/x/netEPSS 0.22%via OSV
CVE-2026-46598Medium· 5.3
4mo ago

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

▾ Sunlitx · golang.org/x/cryptoEPSS 0.52%via OSV
CVE-2026-39833Medium· 5.5⚖ disputed
4mo ago

golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation (CVE-2026-39833)

A flaw was found in golang.org/x/crypto/ssh/agent. The NewKeyring() function, which creates an in-memory keyring, failed to enforce the ConfirmBeforeUse constraint on keys. This allowed keys configured to require user confirmation before u…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.49%via CSAF
CVE-2026-39832Critical· 9.1
4mo ago

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of…

▾ Midnightgolang · cryptoEPSS 0.72%via NVD
CVE-2026-39828Medium· 6.3⚖ disputed
4mo ago

Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succee…

▾ Sunlitgolang.org/x/crypto · golang.org/x/crypto/sshEPSS 0.54%via CVEORG
CVE-2026-39827Medium· 6.5
4mo ago

Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

▾ Sunlitx · golang.org/x/cryptoEPSS 0.28%via OSV
CVE-2026-39830Critical· 9.1
4mo ago

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connec…

▾ Midnightgolang · cryptoEPSS 0.62%via NVD
CVE-2026-39831High· 8.1
4mo ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check (CVE-2026-39831)

A flaw was found in golang.org/x/crypto/ssh. The Verify() method, responsible for FIDO/U2F security key types, did not properly check for user presence. This allowed signatures to be accepted without requiring a physical touch on the hardw…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.49%via CSAF
CVE-2026-42508Critical· 9.1
4mo ago

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

▾ Midnightgolang · cryptoEPSS 0.65%via NVD
CVE-2026-39834Medium· 6.5⚖ disputed
4mo ago

Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh

Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh

▾ Sunlitx · golang.org/x/cryptoEPSS 0.64%via OSV
CVE-2026-46595High· 7.1PoC⚖ disputed
4mo ago

golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (CVE-2026-46595)

A flaw was found in golang.org/x/crypto/ssh. Source-address validation can be skipped when an SSH server configuration uses an authentication callback type other than public key, allowing authorization bypass in misconfigured servers. This…

▾ MidnightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.60%via CSAF
CVE-2026-43499High· 7.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_…

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_…

▾ Midnightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2026-47783High· 8.1
4mo ago

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

▾ Twilightmemcached · memcachedEPSS 1.3%via NVD
CVE-2026-3039High· 7.5
4mo ago

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in …

▾ Twilightisc · bindEPSS 2.3%via NVD
CVE-2026-5946High· 7.5
4mo ago

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

▾ Twilightisc · bindEPSS 1.7%via NVD
CVE-2026-42009High· 7.5
4mo ago

A flaw was found in gnutls

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not cor…

▾ Twilightgnu · gnutlsEPSS 1.1%via NVD
CVE-2025-54518High· 7.0
4mo ago

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

▾ TwilightAMD · AMD EPYC™ 7002 Series ProcessorsEPSS 0.29%via NVD
CVE-2026-44513High· 8.8
4mo ago

Diffusers is the a library for pretrained diffusion models

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omi…

▾ Twilighthuggingface · diffusersEPSS 0.89%via NVD
CVE-2026-44673High· 7.5PoC
4mo ago

libyang is a YANG data modeling language library

libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attack…

▾ MidnightCESNET · libyangEPSS 0.95%via NVD
CVE-2026-44283Medium· 4.3⚖ disputed
4mo ago

etcd: etcd: Authenticated user can bypass RBAC for unauthorized data access (CVE-2026-44283)

A flaw was found in etcd, a distributed key-value store. An authenticated user, without sufficient read or lease-related permissions, could bypass Role-Based Access Control (RBAC) authorization checks. This bypass occurs during transaction…

▾ SunlitRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.27%via CSAF
CVE-2026-7168Medium· 5.3PoC
4mo ago

Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wr…

Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wr…

▾ Twilighthaxx · curlEPSS 0.59%via NVD
CVE-2026-6429Medium· 5.3
4mo ago

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

▾ Sunlithaxx · curlEPSS 0.51%via NVD
CVE-2026-6276High· 7.5PoC⚖ disputed
4mo ago

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…

▾ Midnighthaxx · curlEPSS 0.35%via NVD
CVE-2026-6253Medium· 5.9PoC
4mo ago

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy nee…

▾ Twilighthaxx · curlEPSS 0.75%via NVD
CVE-2026-5545Medium· 6.5
4mo ago

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that sub…

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that sub…

▾ Sunlithaxx · curlEPSS 0.51%via NVD
CVE-2026-42945High· 8.1PoC
4mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expre…

▾ Midnightf5 · dosEPSS 3.4%via NVD
CVE-2026-44248Medium· 5.3⚖ disputed
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDec…

▾ Sunlitnetty · nettyEPSS 0.72%via NVD
CVEs tagged “csaf” — page 88 · VulnSea