Search CVE reports


Toggle filters

1121 – 1130 of 47099 results

Status is adjusted based on your filters.


CVE-2026-88033

Medium priority
Needs evaluation

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...

1 affected package

mongo-java-driver

Package 24.04 LTS
mongo-java-driver Needs evaluation
Show less packages

CVE-2026-88032

Medium priority
Needs evaluation

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party...

1 affected package

mongo-java-driver

Package 24.04 LTS
mongo-java-driver Needs evaluation
Show less packages

CVE-2026-88021

Medium priority

Not in release

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect...

1 affected package

consul

Package 24.04 LTS
consul Not in release
Show less packages

CVE-2026-87107

Medium priority

Not in release

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}}...

1 affected package

consul

Package 24.04 LTS
consul Not in release
Show less packages

CVE-2026-87106

Medium priority

Not in release

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the...

1 affected package

consul

Package 24.04 LTS
consul Not in release
Show less packages

CVE-2026-87090

Medium priority

Not in release

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An...

1 affected package

consul

Package 24.04 LTS
consul Not in release
Show less packages

CVE-2026-89046

Medium priority
Needs evaluation

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass...

1 affected package

zstd-jni-java

Package 24.04 LTS
zstd-jni-java Needs evaluation
Show less packages

CVE-2026-89045

Medium priority
Needs evaluation

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read...

1 affected package

zstd-jni-java

Package 24.04 LTS
zstd-jni-java Needs evaluation
Show less packages

CVE-2026-89044

Medium priority
Needs evaluation

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by...

1 affected package

netty

Package 24.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-88054

Medium priority
Needs evaluation

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or...

1 affected package

tesseract

Package 24.04 LTS
tesseract Needs evaluation
Show less packages