Search CVE reports


Toggle filters

961 – 970 of 37641 results

Status is adjusted based on your filters.


CVE-2026-2581

Medium priority

Not in release

This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests...

1 affected package

node-undici

Package 22.04 LTS
node-undici Not in release
Show less packages

CVE-2026-2229

Medium priority

Not in release

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it...

1 affected package

node-undici

Package 22.04 LTS
node-undici Not in release
Show less packages

CVE-2026-1528

Medium priority

Not in release

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the...

1 affected package

node-undici

Package 22.04 LTS
node-undici Not in release
Show less packages

CVE-2026-1527

Medium priority

Not in release

ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\r\n) to: * Inject arbitrary HTTP headers * Terminate the HTTP request prematurely and...

1 affected package

node-undici

Package 22.04 LTS
node-undici Not in release
Show less packages

CVE-2026-1526

Medium priority

Not in release

The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client...

1 affected package

node-undici

Package 22.04 LTS
node-undici Not in release
Show less packages

CVE-2026-32274

Medium priority
Needs evaluation

Black is the uncompromising Python code formatter. Prior to 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename...

1 affected package

black

Package 22.04 LTS
black Needs evaluation
Show less packages

CVE-2026-32259

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, when a memory allocation fails in the sixel encoder it would be possible to write past the end of a...

1 affected package

imagemagick

Package 22.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-32249

Medium priority
Not affected

Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]),...

1 affected package

vim

Package 22.04 LTS
vim Not affected
Show less packages

CVE-2026-32240

Medium priority
Needs evaluation

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be truncated to a 64-bit integer. In...

1 affected package

capnproto

Package 22.04 LTS
capnproto Needs evaluation
Show less packages

CVE-2026-32239

Medium priority
Needs evaluation

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead. In theory, this bug could...

1 affected package

capnproto

Package 22.04 LTS
capnproto Needs evaluation
Show less packages