Search CVE reports


Toggle filters

2581 – 2590 of 46511 results

Status is adjusted based on your filters.


CVE-2026-73259

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it....

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73258

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing...

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73257

Medium priority

Not in release

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count...

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73256

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting...

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73255

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences in an #include file or #include virtual directive. The...

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73254

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served...

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73253

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack....

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-73251

Medium priority

Not in release

Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init()...

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-63495

Medium priority
Needs evaluation

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An...

1 affected package

libevent

Package 24.04 LTS
libevent Needs evaluation
Show less packages

CVE-2026-63388

Medium priority
Needs evaluation

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into...

1 affected package

libevent

Package 24.04 LTS
libevent Needs evaluation
Show less packages