Search CVE reports


Toggle filters

141 – 150 of 49291 results

Status is adjusted based on your filters.


CVE-2026-61552

Medium priority
Needs evaluation

Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser...

1 affected package

icinga2

Package 20.04 LTS
icinga2 Needs evaluation
Show less packages

CVE-2026-61551

Medium priority
Needs evaluation

Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsing paths are reachable by...

1 affected package

icinga2

Package 20.04 LTS
icinga2 Needs evaluation
Show less packages

CVE-2026-61550

Medium priority
Needs evaluation

Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker...

1 affected package

icinga2

Package 20.04 LTS
icinga2 Needs evaluation
Show less packages

CVE-2026-93579

Medium priority
Needs evaluation

A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation....

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-91149

Medium priority
Needs evaluation

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an...

1 affected package

cockpit

Package 20.04 LTS
cockpit Needs evaluation
Show less packages

CVE-2026-91147

Medium priority
Needs evaluation

A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is...

1 affected package

cockpit

Package 20.04 LTS
cockpit Needs evaluation
Show less packages

CVE-2026-91142

Medium priority
Needs evaluation

A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A...

1 affected package

cockpit

Package 20.04 LTS
cockpit Needs evaluation
Show less packages

CVE-2026-62943

Medium priority
Needs evaluation

btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor but without an end-of-string anchor for the...

1 affected package

btrbk

Package 20.04 LTS
btrbk Needs evaluation
Show less packages

CVE-2026-55556

Medium priority
Not affected

Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an...

1 affected package

rsyslog

Package 20.04 LTS
rsyslog Not affected
Show less packages

CVE-2026-93690

Medium priority
Needs evaluation

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling...

1 affected package

node-uri-js

Package 20.04 LTS
node-uri-js Needs evaluation
Show less packages