Search CVE reports


Toggle filters

1081 – 1090 of 33257 results

Status is adjusted based on your filters.


CVE-2026-67217

Medium priority
Needs evaluation

cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved,...

1 affected package

cjson

Package 26.04 LTS
cjson Needs evaluation
Show less packages

CVE-2026-67216

Medium priority
Needs evaluation

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the...

4 affected packages

cjson, iperf3, mapcache, sail-ocaml

Package 26.04 LTS
cjson Needs evaluation
iperf3 Needs evaluation
mapcache Needs evaluation
sail-ocaml Needs evaluation
Show less packages

CVE-2026-67215

Medium priority
Needs evaluation

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing...

1 affected package

cjson

Package 26.04 LTS
cjson Needs evaluation
Show less packages

CVE-2026-67214

Medium priority
Needs evaluation

nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from...

1 affected package

node-postcss

Package 26.04 LTS
node-postcss Needs evaluation
Show less packages

CVE-2026-67213

Medium priority
Not affected

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and...

1 affected package

node-postcss

Package 26.04 LTS
node-postcss Not affected
Show less packages

CVE-2026-55995

Medium priority
Needs evaluation

A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.

2 affected packages

open-iscsi, open-isns

Package 26.04 LTS
open-iscsi Needs evaluation
open-isns Needs evaluation
Show less packages

CVE-2026-44944

Medium priority
Needs evaluation

An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects open-iscsi: from ? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.

1 affected package

open-iscsi

Package 26.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-44943

Medium priority
Needs evaluation

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers  to create root-owned files outside the database and inject lines into the record. This...

1 affected package

open-iscsi

Package 26.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-56390

Medium priority
Needs evaluation

GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When...

1 affected package

bison

Package 26.04 LTS
bison Needs evaluation
Show less packages

CVE-2026-56389

Medium priority
Needs evaluation

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML...

1 affected package

bison

Package 26.04 LTS
bison Needs evaluation
Show less packages