Search CVE reports


Toggle filters

61 – 70 of 47939 results

Status is adjusted based on your filters.


CVE-2026-93894

Medium priority
Needs evaluation

In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segfault...

2 affected packages

varnish, vinyl-cache

Package 24.04 LTS
varnish Needs evaluation
vinyl-cache Not in release
Show less packages

CVE-2026-93854

Medium priority

Not in release

In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper...

1 affected package

blazar

Package 24.04 LTS
blazar Not in release
Show less packages

CVE-2026-93852

Medium priority

Not in release

In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the...

1 affected package

blazar

Package 24.04 LTS
blazar Not in release
Show less packages

CVE-2026-93753

Medium priority
Needs evaluation

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in...

1 affected package

node-deepmerge

Package 24.04 LTS
node-deepmerge Needs evaluation
Show less packages

CVE-2026-93751

Medium priority
Needs evaluation

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass...

1 affected package

node-uri-js

Package 24.04 LTS
node-uri-js Needs evaluation
Show less packages

CVE-2026-93750

Medium priority
Needs evaluation

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs...

1 affected package

node-got

Package 24.04 LTS
node-got Needs evaluation
Show less packages

CVE-2026-93749

Medium priority
Needs evaluation

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause...

1 affected package

node-postcss

Package 24.04 LTS
node-postcss Needs evaluation
Show less packages

CVE-2026-93748

Medium priority
Needs evaluation

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users....

1 affected package

node-got

Package 24.04 LTS
node-got Needs evaluation
Show less packages

CVE-2026-93690

Medium priority
Needs evaluation

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling...

1 affected package

node-uri-js

Package 24.04 LTS
node-uri-js Needs evaluation
Show less packages

CVE-2026-93687

Medium priority
Needs evaluation

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate...

1 affected package

node-braces

Package 24.04 LTS
node-braces Needs evaluation
Show less packages