Search CVE reports


Toggle filters

331 – 340 of 36483 results

Status is adjusted based on your filters.


CVE-2026-78408

Medium priority
Needs evaluation

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations...

1 affected package

util-linux

Package 26.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-78222

Medium priority
Needs evaluation

A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the...

1 affected package

libnginx-mod-js

Package 26.04 LTS
libnginx-mod-js Needs evaluation
Show less packages

CVE-2026-76642

Medium priority
Needs evaluation

[Unknown description]

1 affected package

util-linux

Package 26.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-74994

Medium priority
Needs evaluation

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-74835

Medium priority
Needs evaluation

The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-73812

Medium priority
Needs evaluation

httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-73276

Medium priority
Needs evaluation

Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-71380

Medium priority
Needs evaluation

Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with a large Content-Length and...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-70409

Medium priority
Needs evaluation

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-70405

Medium priority
Needs evaluation

Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a BER INTEGER whose length field is...

1 affected package

erlang

Package 26.04 LTS
erlang Needs evaluation
Show less packages