Search CVE reports


Toggle filters

1 – 10 of 27399 results

Status is adjusted based on your filters.


CVE-2026-8450

Medium priority
Needs evaluation

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to...

1 affected package

libhttp-daemon-perl

Package 26.04 LTS
libhttp-daemon-perl Needs evaluation
Show less packages

CVE-2026-48962

Medium priority
Needs evaluation

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in...

2 affected packages

libio-compress-perl, perl

Package 26.04 LTS
libio-compress-perl Needs evaluation
perl Needs evaluation
Show less packages

CVE-2026-48961

Medium priority
Needs evaluation

IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID. When decode_ux() in bin/zipdetails handles an Info-ZIP...

2 affected packages

libio-compress-perl, perl

Package 26.04 LTS
libio-compress-perl Needs evaluation
perl Needs evaluation
Show less packages

CVE-2026-48959

Medium priority
Needs evaluation

IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of...

2 affected packages

libio-compress-perl, perl

Package 26.04 LTS
libio-compress-perl Needs evaluation
perl Needs evaluation
Show less packages

CVE-2025-15649

Medium priority
Needs evaluation

IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls...

2 affected packages

libio-compress-perl, perl

Package 26.04 LTS
libio-compress-perl Not affected
perl Needs evaluation
Show less packages

CVE-2026-49017

Medium priority
Needs evaluation

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the...

1 affected package

swift

Package 26.04 LTS
swift Needs evaluation
Show less packages

CVE-2026-49014

Medium priority
Needs evaluation

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute...

1 affected package

gdal

Package 26.04 LTS
gdal Needs evaluation
Show less packages

CVE-2026-47770

Medium priority
Needs evaluation

[Unknown description]

1 affected package

jq

Package 26.04 LTS
jq Needs evaluation
Show less packages

CVE-2026-47766

Medium priority
Needs evaluation

[Unknown description]

1 affected package

crun

Package 26.04 LTS
crun Needs evaluation
Show less packages

CVE-2026-46644

Medium priority
Needs evaluation

[insecure equivalence in symfony/polyfill-intl-idn for ASCII-only xn-- labels]

1 affected package

php-symfony-polyfill

Package 26.04 LTS
php-symfony-polyfill Needs evaluation
Show less packages