Search CVE reports


Toggle filters

341 – 350 of 36775 results

Status is adjusted based on your filters.


CVE-2026-27587

Medium priority

Not in release

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match pattern contains percent-escape sequences (`%xx`)...

1 affected package

caddy

Package 22.04 LTS
caddy Not in release
Show less packages

CVE-2026-27586

Medium priority

Not in release

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA...

1 affected package

caddy

Package 22.04 LTS
caddy Not in release
Show less packages

CVE-2026-27585

Medium priority

Not in release

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It...

1 affected package

caddy

Package 22.04 LTS
caddy Not in release
Show less packages

CVE-2026-27571

Medium priority

Not in release

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. Prior to versions...

1 affected package

nats-server

Package 22.04 LTS
nats-server Not in release
Show less packages

CVE-2026-3102

Medium priority
Not affected

A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the...

1 affected package

libimage-exiftool-perl

Package 22.04 LTS
libimage-exiftool-perl Not affected
Show less packages

CVE-2026-2807

Medium priority
Vulnerable

Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This...

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 22.04 LTS
firefox Not affected
thunderbird Vulnerable
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Ignored
mozjs91 Ignored
mozjs102 Ignored
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2026-2806

Medium priority
Vulnerable

Uninitialized memory in the Graphics: Text component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 22.04 LTS
firefox Not affected
thunderbird Vulnerable
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Ignored
mozjs91 Ignored
mozjs102 Ignored
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2026-2805

Medium priority
Vulnerable

Invalid pointer in the DOM: Core & HTML component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 22.04 LTS
firefox Not affected
thunderbird Vulnerable
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Ignored
mozjs91 Ignored
mozjs102 Ignored
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2026-2804

Medium priority
Vulnerable

Use-after-free in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 22.04 LTS
firefox Not affected
thunderbird Vulnerable
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Ignored
mozjs91 Ignored
mozjs102 Ignored
mozjs115 Not in release
Show all 9 packages Show less packages

CVE-2026-2803

Medium priority
Vulnerable

Information disclosure, mitigation bypass in the Settings UI component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 22.04 LTS
firefox Not affected
thunderbird Vulnerable
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Ignored
mozjs91 Ignored
mozjs102 Ignored
mozjs115 Not in release
Show all 9 packages Show less packages