Security advisories
130 advisories affecting the catalog, most severe first.
Showing 130 advisories.
No advisories match this filter.
| Severity | Advisory | Affected packages | Status |
|---|---|---|---|
| Critical: 9.1 | AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() | openssl | Affected |
| Critical: 9.8 | Untrusted Sender DN Used as Format String in CMP Response Validation | openssl | Affected |
| Critical | llama.cpp Use-After-Free in RPC GRAPH_RECOMPUTE Handler | llama.cpp | Resolved |
| Critical | Libevent: HTTP header handling bugs create risk of access control bypass. | libevent | Under investigation |
| Critical | libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling | libevent | Under investigation |
| Critical | libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c | libssh2 | Under investigation |
| Critical: 9.8 | llama.cpp: Unauthenticated RCE via GRAPH_COMPUTE buffer=0 bypass in llama.cpp RPC backend | llama.cpp | Resolved |
| High: 8.2 | No summary provided. | pcre2 | Under investigation |
| High: 8.0 | No summary provided. | libxml2 | Under investigation |
| High | Redis TLS pending-data list use-after-free | redis | Affected |
| High: 7.5 | Invalid Pointer Dereference in CMP Server via Crafted protectionAlg | openssl | Affected |
| High: 7.5 | QUIC ACK-only Packet Retention Can Cause Memory Exhaustion | openssl | Affected |
| High: 7.5 | Heap Buffer Overflow in CMS Key Unwrapping | openssl | Affected |
| High: 7.5 | Excessive Memory Use Buffering DTLS Records for a Future Epoch | openssl | Affected |
| High: 7.5 | QUIC Server May Trigger Double Free When Processing INITIAL Packet | openssl | Affected |
| High: 7.5 | RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate | openssl | Affected |
| High | act 0.2.81 through 0.2.89 Missing Authorization in the Artifacts V4 Backend | act | Under investigation |
| High | Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode | capstone | Under investigation |
| High: 7.0 | Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server response | libevent | Under investigation |
| High | Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` return value. | libevent | Under investigation |
| High | Libevent: decode_tag_internal() can lead to out-of-bounds read | libevent | Under investigation |
| High: 8.4 | Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via AF_UNIX accept | libevent | Under investigation |
| High | Expat Denial of Service via storeAtts() Quadratic Complexity | expat | Under investigation |
| High: 7.5 | Unbounded Memory Growth in QUIC Server Incoming Channel Queue | openssl | Affected |
| High: 7.5 | Client-Side Memory Leak in OCSP Response Checking | openssl | Affected |
| High: 8.6 | GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. | bison | Under investigation |
| High | libssh2 Heap Buffer Overflow via ETM Cipher Negotiation | libssh2 | Under investigation |
| High | libssh2 Heap Out-of-Bounds Read via publickey subsystem | libssh2 | Under investigation |
| High | libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation | libssh2 | Under investigation |
| High | libssh2 Double-Free Heap Corruption via sftp_open() | libssh2 | Affected |
| High | GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing | wget | Under investigation |
| High: 7.5 | GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer. This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d. | gzip | Under investigation |
| High | libssh2 - Free of Uninitialized Pointer in publickey List Cleanup | libssh2 | Under investigation |
| High | libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation | libssh2 | Under investigation |
| High | libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c | libssh2 | Under investigation |
| High | libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler | libssh2 | Under investigation |
| High: 7.3 | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records. | glibc | Under investigation |
| High: 7.5 | CVE-2026-6069 | nasm | Affected |
| High: 7.5 | CVE-2026-6067 | nasm | Affected |
| High: 7.8 | llama.cpp has a Heap Buffer Overflow via Integer Overflow in GGUF Tensor Parsing | llama.cpp | Resolved |
| High: 7.8 | llama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 Fix | llama.cpp | Resolved |
| High | Heap-buffer-overflow in pcre2_compile_32 | pcre2 | Under investigation |
| High | Heap-buffer-overflow in opj_j2k_read_tile_header | openjpeg | Affected |
| High | Heap-buffer-overflow in btf_ensure_modifiable | libbpf | Under investigation |
| High | Heap-buffer-overflow in opj_jp2_apply_pclr | opencv | Under investigation |
| High: 8.8 | No summary provided. | libxml2 | Under investigation |
| Medium: 5.6 | No summary provided. | libxml2 | Under investigation |
| Medium: 6.9 | No summary provided. | libxml2 | Under investigation |
| Medium: 6.9 | No summary provided. | libxml2 | Under investigation |
| Medium: 6.9 | No summary provided. | libxml2 | Under investigation |
| Medium: 6.9 | No summary provided. | libxml2 | Under investigation |
| Medium: 6.5 | PCRE2: integer overflow in pcre2_compile_32() causes out-of-bounds write on 32-bit systems | pcre2 | Under investigation |
| Medium: 5.7 | PCRE2: out-of-bounds write in pcre2_pattern_convert() with large patterns on 32-bit systems | pcre2 | Under investigation |
| Medium: 5.9 | CMP Indefinite Cache Growth of ExtraCerts | openssl | Affected |
| Medium | Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecode | capstone | Under investigation |
| Medium | Libevent: HTTP Header smuggling | libevent | Under investigation |
| Medium | Libevent: Null Pointer Dereference in `evws_new_session` | libevent | Affected |
| Medium | Libevent: Dangling Pointer in `evbuffer_add_buffer_reference` | libevent | Under investigation |
| Medium: 4.9 | No summary provided. | expat | Under investigation |
| Medium: 5.9 | No summary provided. | expat | Under investigation |
| Medium | The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given. Only empty directories are created outside the destination. Member contents are still extracted inside it. To return to the destination the member's name must contain the destination directory's own final component, so extraction into a secure randomised directory is not affected. This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created. | python | Under investigation |
| Medium | `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching | python | Under investigation |
| Medium | stringprep.map_table_b2() deviates from RFC 3454 Table B.2 | python | Under investigation |
| Medium: 5.1 | Capstone M68K and RISCV `cs_insn_name()` invalid IDs can trigger out-of-bounds reads and process crashes | capstone | Under investigation |
| Medium: 5.5 | ARM check_pop_return use-of-uninitialized-value | capstone | Under investigation |
| Medium: 5.7 | Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch | perl | Under investigation |
| Medium | llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure | llama.cpp | Resolved |
| Medium: 4.4 | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue. | tar | Under investigation |
| Medium: 4.4 | A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction. | tar | Under investigation |
| Medium: 6.3 | GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this behavior allows directing generated files to arbitrary writable locations on the filesystem, potentially overwriting existing files accessible to the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 8d101c19d4d9aaedf83a448c925513742d4efcf0. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. | bison | Under investigation |
| Medium | Out‑of‑bounds Read in GNU coreutils | coreutils | Under investigation |
| Medium: 5.3 | root-side banner file disclosure | cups | Under investigation |
| Medium: 5.5 | GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9 | patch | Under investigation |
| Medium: 5.5 | GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service. This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313 | patch | Under investigation |
| Medium | GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encoding | wget | Under investigation |
| Medium | GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.c | wget | Under investigation |
| Medium | GNU Wget 1.25.0 Integer Overflow via Content-Range Header Parsing | wget | Under investigation |
| Medium: 4.7 | GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269 | gzip | Under investigation |
| Medium | Use-of-uninitialized-value in iup_delta_optimize | harfbuzz | Under investigation |
| Medium: 6.7 | Stack buffer overflow in sample/http-server via unbounded Unix socket path (strcpy) | libevent | Under investigation |
| Medium: 5.7 | CUPS copy_model() creates a predictable PPD tempfile without O_EXCL/O_NOFOLLOW (symlink TOCTOU, lp → root) | cups | Under investigation |
| Medium: 5.4 | LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body | libpng | Under investigation |
| Medium | jq: stack overflow in module loading on mutual `include` | jq | Under investigation |
| Medium: 6.5 | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions. | glibc | Under investigation |
| Medium: 6.5 | CVE-2026-6068 | nasm | Affected |
| Medium | POP3 command injection in user-controlled commands | python | Under investigation |
| Medium: 5.5 | (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file. | numpy | Resolved |
| Medium: 5.5 | __init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file. | numpy | Resolved |
| Low: 2.9 | No summary provided. | libxml2 | Under investigation |
| Low: 2.9 | No summary provided. | libxml2 | Under investigation |
| Low: 3.7 | PCRE2: out-of-bounds reads in pcre2_match() when matching invalid UTF subjects with PCRE2_MATCH_INVALID_UTF | pcre2 | Under investigation |
| Low: 2.9 | PCRE2: out-of-bounds read in pcre2_match() after JIT fallback with invalid UTF | pcre2 | Under investigation |
| Low | GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default | gh | Affected |
| Low | zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits | python | Under investigation |
| Low | broot Terminal Escape Sequence Injection via Unsanitized File and Directory Names in the Tree View | broot | Under investigation |
| Low | Capstone WASM `br_table` instruction-size truncation can cause no-progress disassembly and parser desynchronization | capstone | Under investigation |
| Low | Heap-based Buffer Overflow in GNU coreutils | coreutils | Under investigation |
| Low: 3.3 | Uncontrolled memory allocation in LIEF ELF Note parser (`Note::create`) | lief | Under investigation |
| Low | Stack-Based Buffer Overflow in libxml2 | libxml2 | Under investigation |
| Low: 2.5 | CUPS fax option values bypass the CVE-2026-34980 control-character sanitizer (incomplete fix) | cups | Under investigation |
| Low: 3.3 | CUPS ipp backend status-line injection can update queue PPD and lead to conditional RCE as lp via foomatic-rip | cups | Under investigation |
| Low: 3.3 | Rizin: Double free in cmd_search.c | rizin | Affected |
| Low | WebAssembly Binaryen IRBuilder wasm-ir-builder.cpp makeLocalTee null pointer dereference | binaryen | Affected |
| Low | WebAssembly Binaryen wasm-binary.cpp readExport heap-based overflow | binaryen | Affected |
| Low: 2.9 | PCRE2: uninitialized memory disclosure in pcre2_serialize_encode() | pcre2 | Under investigation |
| Low | UNKNOWN READ in std::__1::__function::__func<cv::PngDecoder::compose_frame | opencv | Under investigation |
| Low | UNKNOWN READ in boost::re_detail_500::basic_regex_formatter<std::__1::ostream_iterator<char, cha | boost | Fix unavailable |
| Low | UNKNOWN READ in init_struct_ops_maps | libbpf | Under investigation |
| Low: 3.3 | A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. | unzip | Under investigation |
| Unknown | When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`). Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`). | curl | Under investigation |
| Unknown | With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the cached store but rejected by the callback-selected store is then incorrectly accepted. | curl | Under investigation |
| Unknown | A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host. | curl | Under investigation |
| Unknown | A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created. | curl | Under investigation |
| Unknown | When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected. | curl | Under investigation |
| Unknown | When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations. | curl | Under investigation |
| Unknown | A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection. | curl | Under investigation |
| Unknown | A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process. | curl | Under investigation |
| Unknown | A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation. | curl | Under investigation |
| Unknown | Integer Overflow in Undo File Entry Size Check in Vim < v9.2.1014 && Vim >= v8.1.0688 | vim | Affected |
| Unknown | Out-of-bounds Access in libvterm Resize Handling in Vim < 9.2.1013 | vim | Affected |
| Unknown | Ex Command Injection via Unescaped '|' in tagfiles() Path (ccomplete.vim StructMembers) | vim | Affected |
| Unknown | Connection created for the wrong upstream for forward_auth + reverse_proxy | caddy | Under investigation |
| Unknown | Bad-cast to cv::PngDecoder from invalid vptr | opencv | Under investigation |
| Unknown | Null-dereference READ in _libssh2_packet_add | libssh2 | Fix unavailable |
| Unknown | Null-dereference READ in session_startup | libssh2 | Affected |
| Unknown | Null-dereference READ in ubsan_GetStackTrace | libssh2 | Affected |
| Unknown | Null-dereference READ in _libssh2_packet_add | libssh2 | Affected |
| Unknown | Incorrect-function-pointer-type in cv::split | opencv | Under investigation |
| Unknown | Null-dereference READ in session_startup | libssh2 | Affected |
| Unknown | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments. | lua51 | Under investigation |