Search CVE reports


Toggle filters

281 – 290 of 53325 results

Status is adjusted based on your filters.


CVE-2026-89134

Medium priority
Needs evaluation

A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName name-constraint check. The CN-as-DNS fallback was gated on cert->subjectCN != NULL && cert->altNames...

1 affected package

wolfssl

Package 22.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-89133

Medium priority
Needs evaluation

wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is an unconstrained CA tier between a name-constrained...

1 affected package

wolfssl

Package 22.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-89102

Medium priority
Needs evaluation

In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. When a wolfSSL client enables OCSP stapling with the...

1 affected package

wolfssl

Package 22.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-15442

Medium priority
Needs evaluation

In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free. If an application ended up getting a...

1 affected package

wolfssl

Package 22.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-100702

Medium priority
Needs evaluation

Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array...

1 affected package

node-nodemailer

Package 22.04 LTS
node-nodemailer Needs evaluation
Show less packages

CVE-2026-100701

Medium priority
Needs evaluation

Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also stores the caller-specific TLS servername. When two direct TLS/SMTPS transports (secure: true)...

1 affected package

node-nodemailer

Package 22.04 LTS
node-nodemailer Needs evaluation
Show less packages

CVE-2026-100700

Medium priority
Needs evaluation

nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long...

1 affected package

node-nodemailer

Package 22.04 LTS
node-nodemailer Needs evaluation
Show less packages

CVE-2026-100699

Medium priority
Needs evaluation

Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser) mishandles addresses whose local-part is a quoted string and that are followed by RFC 5322 comments, allowing...

1 affected package

node-nodemailer

Package 22.04 LTS
node-nodemailer Needs evaluation
Show less packages

CVE-2026-100698

Medium priority
Needs evaluation

Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functions.inc.php. The port capture group requires pure digits anchored to the end of the string, so any server...

1 affected package

adminer

Package 22.04 LTS
adminer Needs evaluation
Show less packages

CVE-2026-100697

Medium priority
Needs evaluation

Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker...

1 affected package

adminer

Package 22.04 LTS
adminer Needs evaluation
Show less packages