Search CVE reports


Toggle filters

21 – 30 of 297 results


CVE-2026-63072

Medium priority

Some fixes available 9 of 18

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Fixed Not in release — —
openssl1.0 Not in release Not in release Not in release — Fixed
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-54874

Low priority

Some fixes available 9 of 19

Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Fixed Not in release — —
openssl1.0 Not in release Not in release Not in release — Fixed
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-18798

Medium priority

Some fixes available 1 of 5

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-14457

Low priority

Some fixes available 1 of 5

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-14456

Medium priority

Some fixes available 1 of 5

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Needs evaluation Not affected Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-54876

Medium priority
Needs evaluation

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Not affected Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Not affected Not affected Needs evaluation
edk2 Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-56848

Medium priority
Needs evaluation

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**,...

1 affected package

nodejs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nodejs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-58045

Medium priority
Needs evaluation

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected. Repeated...

1 affected package

nodejs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nodejs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-58044

Medium priority
Needs evaluation

A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend...

1 affected package

nodejs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nodejs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-58042

Medium priority
Needs evaluation

A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering of this condition can lead to denial of service. This vulnerability affects Node.js...

1 affected package

nodejs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nodejs Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages