Search CVE reports


Toggle filters

31 – 40 of 283 results


CVE-2026-48618

Medium priority
Needs evaluation

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to...

1 affected package

nodejs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nodejs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-48615

Medium priority
Needs evaluation

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured...

1 affected package

nodejs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nodejs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-48931

Medium priority
Needs evaluation

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

1 affected package

nodejs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nodejs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-48937

Medium priority
Needs evaluation

A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**.

1 affected package

nodejs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nodejs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-48617

Medium priority
Needs evaluation

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations....

1 affected package

nodejs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nodejs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-9076

Low priority

Some fixes available 10 of 21

Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key(). Impact...

6 affected packages

openssl-fips, nodejs, edk2, edk2-hwe, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
openssl Fixed Fixed Fixed Fixed Fixed
openssl1.0 Not in release Not in release Not in release — Fixed
Show less packages

CVE-2026-7383

Low priority

Some fixes available 10 of 21

Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow. Impact summary: A heap buffer overflow may lead to a crash or...

6 affected packages

openssl-fips, nodejs, edk2, edk2-hwe, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
openssl Fixed Fixed Fixed Fixed Fixed
openssl1.0 Not in release Not in release Not in release — Fixed
Show less packages

CVE-2026-45447

High priority

Some fixes available 10 of 21

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or...

6 affected packages

openssl-fips, nodejs, edk2, edk2-hwe, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
openssl Fixed Fixed Fixed Fixed Fixed
openssl1.0 Not in release Not in release Not in release — Fixed
Show less packages

CVE-2026-45446

Low priority

Some fixes available 5 of 10

Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages. Impact summary:...

6 affected packages

openssl-fips, nodejs, edk2, edk2-hwe, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Needs evaluation Needs evaluation Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
openssl Fixed Fixed Fixed Not affected Not affected
openssl1.0 Not in release Not in release Not in release — Not affected
Show less packages

CVE-2026-45445

Medium priority

Some fixes available 5 of 10

Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summary: Every message encrypted...

6 affected packages

openssl-fips, nodejs, edk2, edk2-hwe, openssl, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl-fips Not in release Fixed Not in release — —
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Needs evaluation Needs evaluation Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
openssl Fixed Fixed Fixed Not affected Not affected
openssl1.0 Not in release Not in release Not in release — Not affected
Show less packages