Search CVE reports


Toggle filters

371 – 380 of 47936 results

Status is adjusted based on your filters.


CVE-2026-88038

Medium priority
Needs evaluation

cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator,...

1 affected package

node-cookies

Package 20.04 LTS
node-cookies Needs evaluation
Show less packages

CVE-2026-88036

Medium priority
Needs evaluation

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal...

1 affected package

mongo-c-driver

Package 20.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-88033

Medium priority
Needs evaluation

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...

1 affected package

mongo-java-driver

Package 20.04 LTS
mongo-java-driver Needs evaluation
Show less packages

CVE-2026-88032

Medium priority
Needs evaluation

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party...

1 affected package

mongo-java-driver

Package 20.04 LTS
mongo-java-driver Needs evaluation
Show less packages

CVE-2026-88030

Medium priority
Needs evaluation

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...

1 affected package

ruby-mongo

Package 20.04 LTS
ruby-mongo Needs evaluation
Show less packages

CVE-2026-88029

Medium priority
Needs evaluation

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...

1 affected package

pymongo

Package 20.04 LTS
pymongo Needs evaluation
Show less packages

CVE-2026-87910

Medium priority
Needs evaluation

When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to...

12 affected packages

pypy3, python2.7, python3.4, python3.5, python3.6...

Package 20.04 LTS
pypy3 Needs evaluation
python2.7 Needs evaluation
python3.4
python3.5
python3.6
python3.7
python3.8 Needs evaluation
python3.9 Needs evaluation
python3.10
python3.11
python3.12
python3.14
Show all 12 packages Show less packages

CVE-2026-87908

Medium priority
Needs evaluation

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single...

1 affected package

node-multiparty

Package 20.04 LTS
node-multiparty Needs evaluation
Show less packages

CVE-2026-87776

Medium priority
Needs evaluation

compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never...

1 affected package

node-compression

Package 20.04 LTS
node-compression Needs evaluation
Show less packages

CVE-2026-87106

Medium priority
Needs evaluation

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the...

1 affected package

consul

Package 20.04 LTS
consul Needs evaluation
Show less packages