Search CVE reports


Toggle filters

81 – 90 of 33222 results

Status is adjusted based on your filters.


CVE-2026-33916

Medium priority
Needs evaluation

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials`...

1 affected package

node-handlebars

Package 24.04 LTS
node-handlebars Needs evaluation
Show less packages

CVE-2026-33896

Medium priority

Not in release

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an...

1 affected package

node-node-forge

Package 24.04 LTS
node-node-forge Not in release
Show less packages

CVE-2026-33895

Medium priority

Not in release

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not...

1 affected package

node-node-forge

Package 24.04 LTS
node-node-forge Not in release
Show less packages

CVE-2026-33894

Medium priority

Not in release

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3)....

1 affected package

node-node-forge

Package 24.04 LTS
node-node-forge Not in release
Show less packages

CVE-2026-33891

Medium priority

Not in release

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the...

1 affected package

node-node-forge

Package 24.04 LTS
node-node-forge Not in release
Show less packages

CVE-2026-34475

Medium priority
Needs evaluation

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

1 affected package

varnish

Package 24.04 LTS
varnish Needs evaluation
Show less packages

CVE-2026-33871

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of...

1 affected package

netty

Package 24.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-33870

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling...

1 affected package

netty

Package 24.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-28369

Medium priority
Needs evaluation

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates...

1 affected package

undertow

Package 24.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-28368

Medium priority
Needs evaluation

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header...

1 affected package

undertow

Package 24.04 LTS
undertow Needs evaluation
Show less packages