Search CVE reports


Toggle filters

211 – 220 of 42812 results

Status is adjusted based on your filters.


CVE-2026-34826

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header without limiting the number of individual byte ranges. Although the existing fix...

1 affected package

ruby-rack

Package 18.04 LTS
ruby-rack Needs evaluation
Show less packages

CVE-2026-34786

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules evaluates several header_rules types against the raw URL-encoded PATH_INFO, while the underlying file-serving...

1 affected package

ruby-rack

Package 18.04 LTS
ruby-rack Needs evaluation
Show less packages

CVE-2026-34785

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL...

1 affected package

ruby-rack

Package 18.04 LTS
ruby-rack Needs evaluation
Show less packages

CVE-2026-34763

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates the configured root path directly into a regular expression when deriving the displayed directory path. If root...

1 affected package

ruby-rack

Package 18.04 LTS
ruby-rack Needs evaluation
Show less packages

CVE-2026-34230

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encoding processes Accept-Encoding values with quadratic time complexity when the header contains many wildcard (*)...

1 affected package

ruby-rack

Package 18.04 LTS
ruby-rack Needs evaluation
Show less packages

CVE-2026-26961

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extracts the boundary parameter from multipart/form-data using a greedy regular expression. When a Content-Type...

1 affected package

ruby-rack

Package 18.04 LTS
ruby-rack Needs evaluation
Show less packages

CVE-2025-65114

Medium priority
Needs evaluation

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recommended to upgrade to version 9.2.13...

1 affected package

trafficserver

Package 18.04 LTS
trafficserver Needs evaluation
Show less packages

CVE-2025-58136

Medium priority
Needs evaluation

A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or...

1 affected package

trafficserver

Package 18.04 LTS
trafficserver Needs evaluation
Show less packages

CVE-2026-34876

Medium priority
Needs evaluation

An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with...

1 affected package

mbedtls

Package 18.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2026-33691

Medium priority
Needs evaluation

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with...

1 affected package

modsecurity-crs

Package 18.04 LTS
modsecurity-crs Needs evaluation
Show less packages