Search CVE reports
101 – 110 of 36262 results
Not in release
HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss...
1 affected package
python-httpx2
| Package | 26.04 LTS |
|---|---|
| python-httpx2 | Not in release |
Not in release
HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a...
1 affected package
python-httpx2
| Package | 26.04 LTS |
|---|---|
| python-httpx2 | Not in release |
Not in release
HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files=...
1 affected package
python-httpx2
| Package | 26.04 LTS |
|---|---|
| python-httpx2 | Not in release |
Not in release
HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered text in _SSELineDecoder.decode() when an...
1 affected package
python-httpx2
| Package | 26.04 LTS |
|---|---|
| python-httpx2 | Not in release |
libjxl before 0.12 contains an integer underflow vulnerability in the container box parser that allows remote attackers to inject arbitrary metadata by exploiting 64-bit box size truncation to size_t on 32-bit platforms. Attackers...
1 affected package
jpeg-xl
| Package | 26.04 LTS |
|---|---|
| jpeg-xl | Needs evaluation |
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected...
1 affected package
libnginx-mod-js
| Package | 26.04 LTS |
|---|---|
| libnginx-mod-js | Needs evaluation |
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established...
10 affected packages
golang-1.17, golang-1.20, golang-1.21, golang-1.22, golang-1.23...
| Package | 26.04 LTS |
|---|---|
| golang-1.17 | Not in release |
| golang-1.20 | Not in release |
| golang-1.21 | Not in release |
| golang-1.22 | Not in release |
| golang-1.23 | Needs evaluation |
| golang-1.24 | Needs evaluation |
| golang-1.25 | Needs evaluation |
| golang-1.26 | Needs evaluation |
| golang-1.27 | Not in release |
| golang-defaults | Needs evaluation |
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor...
1 affected package
util-linux
| Package | 26.04 LTS |
|---|---|
| util-linux | Needs evaluation |
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep...
1 affected package
util-linux
| Package | 26.04 LTS |
|---|---|
| util-linux | Needs evaluation |
The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations...
1 affected package
util-linux
| Package | 26.04 LTS |
|---|---|
| util-linux | Needs evaluation |