Search CVE reports


Toggle filters

1 – 10 of 297 results


CVE-2026-54873

Low priority
Vulnerable

Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Vulnerable Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Vulnerable Not affected Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-42772

Low priority
Vulnerable

Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Vulnerable Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Vulnerable Not affected Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-84784

Low priority

Some fixes available 1 of 4

Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Vulnerable Not affected Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-84783

Medium priority
Vulnerable

Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Not affected Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Not affected Not affected Not affected Not affected Not affected
edk2-hwe Not affected Not in release Not in release — —
Show less packages

CVE-2026-84782

High priority

Some fixes available 8 of 18

Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Not in release Not in release — —
openssl1.0 Not in release Not in release Not in release — Fixed
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-77696

Low priority

Some fixes available 8 of 18

Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Not in release Not in release — —
openssl1.0 Not in release Not in release Not in release — Fixed
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-75806

Low priority

Some fixes available 3 of 18

Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Needs evaluation Needs evaluation
openssl-fips Not in release Not in release Not in release — —
openssl1.0 Not in release Not in release Not in release — Needs evaluation
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-75805

Low priority

Some fixes available 3 of 7

Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Not in release Not in release — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Needs evaluation Needs evaluation Not affected Not affected Not affected
edk2-hwe Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-75804

Low priority

Some fixes available 1 of 4

Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Vulnerable Not affected Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages

CVE-2026-72897

Low priority

Some fixes available 1 of 4

Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected — —
openssl1.0 Not in release Not in release Not in release — Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
edk2 Vulnerable Not affected Not affected Not affected Not affected
edk2-hwe Vulnerable Not in release Not in release — —
Show less packages