Search CVE reports


Toggle filters

21 – 30 of 33539 results

Status is adjusted based on your filters.


CVE-2026-34079

Medium priority
Needs evaluation

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache...

1 affected package

flatpak

Package 24.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-34078

Medium priority
Needs evaluation

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run...

1 affected package

flatpak

Package 24.04 LTS
flatpak Needs evaluation
Show less packages

CVE-2026-34080

Medium priority
Needs evaluation

xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop...

1 affected package

xdg-dbus-proxy

Package 24.04 LTS
xdg-dbus-proxy Needs evaluation
Show less packages

CVE-2026-29181

Medium priority
Needs evaluation

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker...

1 affected package

golang-opentelemetry-otel

Package 24.04 LTS
golang-opentelemetry-otel Needs evaluation
Show less packages

CVE-2026-39395

Medium priority

Not in release

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads...

1 affected package

cosign

Package 24.04 LTS
cosign Not in release
Show less packages

CVE-2026-39373

Medium priority
Needs evaluation

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for...

1 affected package

python-jwcrypto

Package 24.04 LTS
python-jwcrypto Needs evaluation
Show less packages

CVE-2026-39324

Medium priority
Needs evaluation

Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryption fails, the implementation...

2 affected packages

ruby-rack-session, ruby-rack

Package 24.04 LTS
ruby-rack-session Not in release
ruby-rack Needs evaluation
Show less packages

CVE-2026-4631

Medium priority
Needs evaluation

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single...

1 affected package

cockpit

Package 24.04 LTS
cockpit Needs evaluation
Show less packages

CVE-2026-39316

Medium priority
Needs evaluation

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a use-after-free vulnerability exists in the CUPS scheduler (cupsd) when temporary printers are...

1 affected package

cups

Package 24.04 LTS
cups Needs evaluation
Show less packages

CVE-2026-39314

Medium priority
Needs evaluation

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, an integer underflow vulnerability in _ppdCreateFromIPP() (cups/ppd-cache.c) allows any...

1 affected package

cups

Package 24.04 LTS
cups Needs evaluation
Show less packages