Search CVE reports


Toggle filters

41 – 50 of 40128 results

Status is adjusted based on your filters.


CVE-2026-102560

Medium priority
Needs evaluation

A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated...

2 affected packages

libsoup2.4, libsoup3

Package 26.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-102559

Medium priority
Needs evaluation

A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full...

2 affected packages

libsoup2.4, libsoup3

Package 26.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-102558

Medium priority
Needs evaluation

A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer...

2 affected packages

libsoup2.4, libsoup3

Package 26.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-102555

Medium priority
Needs evaluation

A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded...

2 affected packages

libsoup2.4, libsoup3

Package 26.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-102635

Medium priority
Needs evaluation

ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number...

1 affected package

imagemagick

Package 26.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-102633

Medium priority
Needs evaluation

libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with...

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 26.04 LTS
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 Not in release
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Not in release
cadaver Needs evaluation
gdcm Not affected
ayttm Not in release
cableswig Not in release
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk Not in release
smart Not in release
firefox Not affected
thunderbird Not affected
libxmltok Not in release
Show all 23 packages Show less packages

CVE-2026-102557

Medium priority
Needs evaluation

A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments...

2 affected packages

libsoup2.4, libsoup3

Package 26.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-102556

Medium priority
Needs evaluation

A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting...

2 affected packages

libsoup2.4, libsoup3

Package 26.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-102601

Medium priority
Needs evaluation

Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats...

1 affected package

php-league-flysystem

Package 26.04 LTS
php-league-flysystem Needs evaluation
Show less packages

CVE-2026-102598

Medium priority
Needs evaluation

Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first...

1 affected package

python-werkzeug

Package 26.04 LTS
python-werkzeug Needs evaluation
Show less packages