Search CVE reports


Toggle filters

331 – 340 of 45341 results

Status is adjusted based on your filters.


CVE-2026-56854

Medium priority
Needs evaluation

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions...

4 affected packages

golang-go.crypto, snapd, lxd, google-guest-agent

Package 24.04 LTS
golang-go.crypto Needs evaluation
snapd Needs evaluation
lxd Not in release
google-guest-agent Needs evaluation
Show less packages

CVE-2026-37236

Medium priority
Needs evaluation

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type...

1 affected package

golang-github-grpc-ecosystem-grpc-gateway

Package 24.04 LTS
golang-github-grpc-ecosystem-grpc-gateway Needs evaluation
Show less packages

CVE-2026-15603

Medium priority
Needs evaluation

morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line...

1 affected package

node-morgan

Package 24.04 LTS
node-morgan Needs evaluation
Show less packages

CVE-2026-82255

Medium priority
Needs evaluation

gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because...

1 affected package

rust-gix-transport

Package 24.04 LTS
rust-gix-transport Needs evaluation
Show less packages

CVE-2026-82254

Medium priority

Not in release

gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to...

1 affected package

rust-gix-pack

Package 24.04 LTS
rust-gix-pack Not in release
Show less packages

CVE-2026-82253

Medium priority
Needs evaluation

gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via...

2 affected packages

rust-gix, rust-gix-validate

Package 24.04 LTS
rust-gix Not in release
rust-gix-validate Needs evaluation
Show less packages

CVE-2026-82252

Medium priority

Not in release

gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked...

1 affected package

rust-gix

Package 24.04 LTS
rust-gix Not in release
Show less packages

CVE-2026-82251

Medium priority

Not in release

gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to...

1 affected package

rust-gix

Package 24.04 LTS
rust-gix Not in release
Show less packages

CVE-2026-82250

Medium priority
Needs evaluation

gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band...

1 affected package

rust-gix-packetline

Package 24.04 LTS
rust-gix-packetline Needs evaluation
Show less packages

CVE-2026-82249

Medium priority
Needs evaluation

gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and...

1 affected package

rust-gix-credentials

Package 24.04 LTS
rust-gix-credentials Needs evaluation
Show less packages