Search CVE reports
331 – 340 of 45341 results
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions...
4 affected packages
golang-go.crypto, snapd, lxd, google-guest-agent
| Package | 24.04 LTS |
|---|---|
| golang-go.crypto | Needs evaluation |
| snapd | Needs evaluation |
| lxd | Not in release |
| google-guest-agent | Needs evaluation |
grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type...
1 affected package
golang-github-grpc-ecosystem-grpc-gateway
| Package | 24.04 LTS |
|---|---|
| golang-github-grpc-ecosystem-grpc-gateway | Needs evaluation |
morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line...
1 affected package
node-morgan
| Package | 24.04 LTS |
|---|---|
| node-morgan | Needs evaluation |
gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because...
1 affected package
rust-gix-transport
| Package | 24.04 LTS |
|---|---|
| rust-gix-transport | Needs evaluation |
Not in release
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to...
1 affected package
rust-gix-pack
| Package | 24.04 LTS |
|---|---|
| rust-gix-pack | Not in release |
gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via...
2 affected packages
rust-gix, rust-gix-validate
| Package | 24.04 LTS |
|---|---|
| rust-gix | Not in release |
| rust-gix-validate | Needs evaluation |
Not in release
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked...
1 affected package
rust-gix
| Package | 24.04 LTS |
|---|---|
| rust-gix | Not in release |
Not in release
gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to...
1 affected package
rust-gix
| Package | 24.04 LTS |
|---|---|
| rust-gix | Not in release |
gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band...
1 affected package
rust-gix-packetline
| Package | 24.04 LTS |
|---|---|
| rust-gix-packetline | Needs evaluation |
gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and...
1 affected package
rust-gix-credentials
| Package | 24.04 LTS |
|---|---|
| rust-gix-credentials | Needs evaluation |