VulnSea

Tagged “vex”

CVEs tagged vex, newest first.

2265 CVEsRSS

CVE-2026-10832Medium· 5.9
3d ago

A flaw was found in the DERDecoder class within wildfly-elytron-asn1

A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to…

SunlitRed Hat · wildfly-elytron-asn1EPSS 0.28%via NVD
CVE-2026-93676Low· 3.2
3d ago

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bu…

SunlitRed Hat · xdg-dbus-proxyEPSS 0.10%via NVD
CVE-2026-93653Medium· 5.5
3d ago

A denial of service flaw was found in Poppler's Splash backend

A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count that dr…

SunlitRed Hat · popplerEPSS 0.11%via NVD
CVE-2026-93567High· 7.5
3d ago

A flaw was found in Netty's HTTP/2 codec

A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker …

TwilightRed Hat · netty-codec-http2EPSS 0.40%via NVD
CVE-2026-93568High· 7.5
3d ago

A flaw was found in Netty

A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object conversion path incorrectly processes these requests as regular HT…

TwilightRed Hat · netty-codec-http2EPSS 0.47%via NVD
CVE-2026-93576High· 7.5
3d ago

A flaw was found in Netty netty-codec-smtp

A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this…

TwilightRed Hat · netty-codec-smtpEPSS 0.27%via NVD
CVE-2026-93569High· 8.2
3d ago

A flaw was found in Netty

A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, …

TwilightRed Hat · netty-codec-http2EPSS 0.37%via NVD
CVE-2026-93560High· 7.5
3d ago

A flaw was found in the Netty STOMP codec

A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an infinite dec…

TwilightRed Hat · netty-codec-stompEPSS 0.41%via NVD
CVE-2026-93492Medium· 5.3
3d ago

A flaw was found in Netty's HTTP/2 HpackEncoder

A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of unique headers, l…

SunlitRed Hat · netty-codec-http2EPSS 0.30%via NVD
CVE-2026-93491High· 7.5
3d ago

A flaw was found in Netty's HttpServerCodec

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to gr…

TwilightRed Hat · netty-codec-httpEPSS 0.44%via NVD
CVE-2026-93488High· 7.5
3d ago

A flaw was found in Netty

A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can…

TwilightRed Hat · netty-codec-httpEPSS 0.46%via NVD
CVE-2026-93578Medium· 5.9PoC
3d ago

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate is…

TwilightRed Hat · netty-handler-ssl-ocspEPSS 0.23%via NVD
CVE-2026-93575High· 7.5
3d ago

A flaw was found in Netty's MqttDecoder

A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against the 'Re…

TwilightRed Hat · netty-codec-mqttEPSS 0.39%via NVD
CVE-2026-93572High· 7.5
3d ago

A flaw was found in Netty's `RedisArrayAggregator` component

A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to eagerly prealloca…

TwilightRed Hat · netty-codec-redisEPSS 0.34%via NVD
CVE-2026-93563High· 7.5
3d ago

A flaw was found in Netty's `SmtpResponseDecoder` component

A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP response without …

TwilightRed Hat · netty-codec-smtpEPSS 0.33%via NVD
CVE-2026-81627High· 8.2PoC
3d ago

A flaw was found in QEMU

A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over locked S…

MidnightRed Hat · qemu-kvmEPSS 0.20%via NVD
CVE-2026-93561Medium· 6.5
3d ago

A flaw was found in io.netty/netty-codec-memcache

A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server ca…

SunlitRed Hat · netty-codec-memcacheEPSS 0.18%via NVD
CVE-2026-87743High· 7.5
3d ago

A flaw was found in Quarkus HTTP security

A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the attacker to craft a URL that the secu…

TwilightRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.43%via NVD
CVE-2026-93494High· 7.5
3d ago

A flaw was found in Netty's StompSubframeDecoder component

A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf…

TwilightRed Hat · netty-codec-stompEPSS 0.41%via NVD
CVE-2026-93493Medium· 5.9
3d ago

A flaw was found in Netty's `netty-handler-ssl-ocsp` component

A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that omits the optional `nextUpdate` field. This omission…

SunlitRed Hat · netty-handler-ssl-ocspEPSS 0.22%via NVD
CVE-2026-89059High· 7.5PoC
3d ago

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafte…

MidnightRed Hat · RESTEasyEPSS 0.56%via NVD
CVE-2026-89058High· 7.4PoC
3d ago

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. Thi…

MidnightRed Hat · RESTEasyEPSS 0.42%via NVD
CVE-2026-90997High· 7.4
4d ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vuln…

TwilightKeycloak · keycloak-servicesEPSS 0.40%via NVD
CVE-2026-8674Medium· 5.3
4d ago

Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assert…

Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assert…

SunlitThe GNU C Library · glibcEPSS 0.31%via NVD
CVE-2026-86864High· 8.8
4d ago

pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation

pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options…

Twilightpgadmin · pgadmin_4EPSS 0.38%via NVD
CVE-2026-86863Critical· 9.8
4d ago

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEB…

Midnightpgadmin · pgadmin_4EPSS 0.36%via NVD
CVE-2026-86862Medium· 6.5
4d ago

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connecti…

Sunlitpgadmin · pgadmin_4EPSS 0.20%via NVD
CVE-2026-86861Medium· 5.9
4d ago

pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call

pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-…

Sunlitpgadmin · pgadmin_4EPSS 0.44%via NVD
CVE-2026-86000Medium· 5.3PoC
4d ago

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and V…

Twilightfacelessuser · soupsieveEPSS 0.44%via NVD
CVE-2026-85999Medium· 5.3
4d ago

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used …

Sunlitfacelessuser · soupsieveEPSS 0.35%via NVD
CVEs tagged “vex” — page 2 · VulnSea