Home / Security / CVE index / 2026

2026 NetApp CVEs

Showing 300 CVEs with a 2026 identifier — page 1 of 4. Sorted by CVE id.

Always verify. NetApp's advisory is authoritative for affected versions and fixes; NVD carries the CVSS record.
Showing 300 of 300
CVEPublishedSeverityCVSSSummary / Sources
CVE-2026-06032026-01-23HIGH8.3A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, un NVD ↗ · NTAP-20260508-0018
CVE-2026-06362026-04-15MEDIUM6.5Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (pr NVD ↗ · NTAP-20260917-0008
CVE-2026-0672——— NVD ↗ · NTAP-20260130-0007
CVE-2026-0846——— NVD ↗ · NTAP-20260917-0001
CVE-2026-08472026-03-04HIGH7.5A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCor NVD ↗ · NTAP-20260917-0001
CVE-2026-08482026-03-05CRITICAL10.0NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads NVD ↗ · NTAP-20260917-0001
CVE-2026-0861——— NVD ↗ · NTAP-20260320-0005
CVE-2026-0865——— NVD ↗ · NTAP-20260305-0014
CVE-2026-09152026-01-15HIGH7.5Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued netwo NVD ↗ · NTAP-20260313-0003
CVE-2026-09642026-03-26MEDIUM6.3A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused NVD ↗ · NTAP-20260501-0015
CVE-2026-09652026-03-26LOW3.3A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious NVD ↗ · NTAP-20260501-0015
CVE-2026-09662026-03-26HIGH8.2A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remo NVD ↗ · NTAP-20260501-0015
CVE-2026-09672026-03-26MEDIUM5.5A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processe NVD ↗ · NTAP-20260501-0015
CVE-2026-09682026-03-26LOW3.1A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH NVD ↗ · NTAP-20260501-0015
CVE-2026-0988——— NVD ↗ · NTAP-20260320-0004
CVE-2026-09902026-01-15MEDIUM5.9A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalo NVD ↗ · NTAP-20260220-0013
CVE-2026-0992——— NVD ↗ · NTAP-20260220-0012
CVE-2026-10109——— NVD ↗ · NTAP-20260626-0007
CVE-2026-10534——— NVD ↗ · NTAP-20260814-0007
CVE-2026-10535——— NVD ↗ · NTAP-20260717-0005
CVE-2026-10543——— NVD ↗ · NTAP-20260814-0008
CVE-2026-106492026-06-16HIGH8.6A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By NVD ↗ · NTAP-20260917-0003
CVE-2026-10695——— NVD ↗ · NTAP-20260717-0002
CVE-2026-10723——— NVD ↗ · NTAP-20260730-0002
CVE-2026-10822——— NVD ↗ · NTAP-20260730-0003
CVE-2026-10846——— NVD ↗ · NTAP-20260619-0016
CVE-2026-11331——— NVD ↗ · NTAP-20260730-0008
CVE-2026-11564——— NVD ↗ · NTAP-20260731-0005
CVE-2026-11605——— NVD ↗ · NTAP-20260730-0009
CVE-2026-11622——— NVD ↗ · NTAP-20260730-0007
CVE-2026-11721——— NVD ↗ · NTAP-20260730-0004
CVE-2026-118222026-06-09HIGH7.8SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exh NVD ↗ · NTAP-20260925-0015
CVE-2026-118242026-06-09HIGH7.8SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execut NVD ↗ · NTAP-20260925-0016
CVE-2026-11856——— NVD ↗ · NTAP-20260731-0002
CVE-2026-1188——— NVD ↗ · NTAP-20260410-0015
CVE-2026-11906——— NVD ↗ · NTAP-20260626-0010
CVE-2026-11972——— NVD ↗ · NTAP-20260903-0009
CVE-2026-1207——— NVD ↗ · NTAP-20260305-0001
CVE-2026-1225——— NVD ↗ · NTAP-20260305-0008
CVE-2026-1245——— NVD ↗ · NTAP-20260821-0002
CVE-2026-12617——— NVD ↗ · NTAP-20260730-0005
CVE-2026-1285——— NVD ↗ · NTAP-20260305-0001
CVE-2026-1287——— NVD ↗ · NTAP-20260305-0001
CVE-2026-1299——— NVD ↗ · NTAP-20260717-0014
CVE-2026-1312——— NVD ↗ · NTAP-20260305-0001
CVE-2026-13204——— NVD ↗ · NTAP-20260730-0006
CVE-2026-13321——— NVD ↗ · NTAP-20260730-0001
CVE-2026-1352——— NVD ↗ · NTAP-20260422-0014
CVE-2026-137572026-06-29MEDIUM6.2A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a NVD ↗ · NTAP-20261002-0019
CVE-2026-141642026-06-30HIGH7.5A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain sta NVD ↗ · NTAP-20260925-0023
CVE-2026-14266——— NVD ↗ · NTAP-20260724-0010
CVE-2026-14456——— NVD ↗ · NTAP-20260821-0003
CVE-2026-14457——— NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0003
CVE-2026-147422026-07-05LOW3.1A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_interna NVD ↗ · NTAP-20260917-0001
CVE-2026-1484——— NVD ↗ · NTAP-20260320-0003
CVE-2026-1485——— NVD ↗ · NTAP-20260320-0001
CVE-2026-1489——— NVD ↗ · NTAP-20260320-0002
CVE-2026-1519——— NVD ↗ · NTAP-20260403-0003
CVE-2026-15308——— NVD ↗ · NTAP-20260717-0016
CVE-2026-15370——— NVD ↗ · NTAP-20260807-0007
CVE-2026-15571——— NVD ↗ · NTAP-20260828-0007
CVE-2026-155882026-07-20MEDIUM5.3A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce NVD ↗ · NTAP-20260924-0030
CVE-2026-15612026-03-25MEDIUM5.4IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is vulnerable to server-side request forgery (SSRF NVD ↗ · NTAP-20260917-0001
CVE-2026-1577——— NVD ↗ · NTAP-20260422-0009
CVE-2026-159552026-09-14HIGH7.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file pat NVD ↗ · NTAP-20260917-0006
CVE-2026-15995——— NVD ↗ · NTAP-20260724-0014
CVE-2026-1642——— NVD ↗ · NTAP-20260313-0008
CVE-2026-16480——— NVD ↗ · NTAP-20260814-0011
CVE-2026-16702——— NVD ↗ · NTAP-20260917-0009
CVE-2026-17106——— NVD ↗ · NTAP-20260828-0017
CVE-2026-1718——— NVD ↗ · NTAP-20260529-0007
CVE-2026-174632026-09-14MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker t NVD ↗ · NTAP-20260917-0010
CVE-2026-1757——— NVD ↗ · NTAP-20260220-0011
CVE-2026-18096——— NVD ↗ · NTAP-20260814-0012
CVE-2026-18097——— NVD ↗ · NTAP-20260814-0009
CVE-2026-184012026-08-04MEDIUM6.9The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 char NVD ↗ · NTAP-20260930-0002
CVE-2026-18798——— NVD ↗ · NTAP-20260903-0001 · NTAP-20260902-0004
CVE-2026-18963——— NVD ↗ · NTAP-20260828-0006
CVE-2026-190332026-09-16MEDIUM6.5For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG s NVD ↗ · NTAP-20260930-0010
CVE-2026-1933——— NVD ↗ · NTAP-20260527-0005
CVE-2026-19652026-03-11MEDIUM6.5libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recen NVD ↗ · NTAP-20260327-0002
CVE-2026-196622026-09-16MEDIUM5.9An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone NVD ↗ · NTAP-20260930-0011
CVE-2026-196662026-09-16HIGH7.5On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process wi NVD ↗ · NTAP-20260930-0003
CVE-2026-196672026-09-16HIGH7.5If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache ent NVD ↗ · NTAP-20260930-0004
CVE-2026-196682026-09-16MEDIUM5.3A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default li NVD ↗ · NTAP-20260930-0015
CVE-2026-199412026-09-16MEDIUM5.9An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream lev NVD ↗ · NTAP-20260930-0012
CVE-2026-2005——— NVD ↗ · NTAP-20260515-0001
CVE-2026-2006——— NVD ↗ · NTAP-20260515-0002
CVE-2026-20652——— NVD ↗ · NTAP-20260429-0010
CVE-2026-21226——— NVD ↗ · NTAP-20260410-0001
CVE-2026-21441——— NVD ↗ · NTAP-20260130-0010
CVE-2026-21636——— NVD ↗ · NTAP-20260311-0014
CVE-2026-21637——— NVD ↗ · NTAP-20260313-0009
CVE-2026-21710——— NVD ↗ · NTAP-20260410-0013
CVE-2026-217112026-03-30MEDIUM5.3A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all compa NVD ↗ · NTAP-20261002-0020
CVE-2026-21712——— NVD ↗ · NTAP-20260410-0010
CVE-2026-217132026-03-30MEDIUM5.9A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proport NVD ↗ · NTAP-20260925-0020
CVE-2026-21714——— NVD ↗ · NTAP-20260410-0012
CVE-2026-21717——— NVD ↗ · NTAP-20260410-0011
CVE-2026-21925——— NVD ↗ · NTAP-20260123-0012
CVE-2026-21929——— NVD ↗ · NTAP-20260123-0010
CVE-2026-21932——— NVD ↗ · NTAP-20260123-0012
CVE-2026-21933——— NVD ↗ · NTAP-20260123-0012
CVE-2026-21936——— NVD ↗ · NTAP-20260123-0009
CVE-2026-21937——— NVD ↗ · NTAP-20260123-0009
CVE-2026-21941——— NVD ↗ · NTAP-20260123-0009
CVE-2026-21945——— NVD ↗ · NTAP-20260123-0012
CVE-2026-21947——— NVD ↗ · NTAP-20260123-0013
CVE-2026-21948——— NVD ↗ · NTAP-20260123-0009
CVE-2026-21949——— NVD ↗ · NTAP-20260123-0010
CVE-2026-21950——— NVD ↗ · NTAP-20260123-0010
CVE-2026-21952——— NVD ↗ · NTAP-20260123-0010
CVE-2026-21964——— NVD ↗ · NTAP-20260123-0009
CVE-2026-21965——— NVD ↗ · NTAP-20260123-0010
CVE-2026-21968——— NVD ↗ · NTAP-20260123-0009
CVE-2026-21998——— NVD ↗ · NTAP-20260429-0005
CVE-2026-22001——— NVD ↗ · NTAP-20260429-0005
CVE-2026-22002——— NVD ↗ · NTAP-20260429-0005
CVE-2026-22003——— NVD ↗ · NTAP-20260429-0009
CVE-2026-22004——— NVD ↗ · NTAP-20260429-0005
CVE-2026-22005——— NVD ↗ · NTAP-20260429-0005
CVE-2026-220072026-04-21LOW2.9Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versio NVD ↗ · NTAP-20260917-0001 · NTAP-20260717-0008 +1
CVE-2026-220082026-04-21LOW3.7Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to exploit vulnerability all NVD ↗ · NTAP-20260917-0001 · NTAP-20260429-0008
CVE-2026-22009——— NVD ↗ · NTAP-20260429-0005
CVE-2026-220132026-04-21MEDIUM5.3Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions t NVD ↗ · NTAP-20260917-0001 · NTAP-20260717-0008 +1
CVE-2026-22015——— NVD ↗ · NTAP-20260429-0005
CVE-2026-220162026-04-21HIGH7.5Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions t NVD ↗ · NTAP-20260917-0001 · NTAP-20260429-0012
CVE-2026-22017——— NVD ↗ · NTAP-20260429-0005
CVE-2026-220182026-04-21LOW3.7Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versi NVD ↗ · NTAP-20260917-0001 · NTAP-20260429-0012
CVE-2026-220212026-04-21MEDIUM5.3Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions t NVD ↗ · NTAP-20260917-0001 · NTAP-20260717-0008 +1
CVE-2026-22048——— NVD ↗ · NTAP-20260217-0001
CVE-2026-220492026-07-22HIGH8.8ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID w NVD ↗ · NTAP-20260722-0001
CVE-2026-220502026-01-12MEDIUM4.3ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privil NVD ↗ · NTAP-20260112-0001
CVE-2026-22051——— NVD ↗ · NTAP-20260420-0001
CVE-2026-220522026-03-05MEDIUM4.3ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated NVD ↗ · NTAP-20260304-0001
CVE-2026-22054——— NVD ↗ · NTAP-20260603-0001
CVE-2026-22055——— NVD ↗ · NTAP-20260603-0002
CVE-2026-22056——— NVD ↗ · NTAP-20260828-0021
CVE-2026-22610——— NVD ↗ · NTAP-20260311-0001
CVE-2026-22695——— NVD ↗ · NTAP-20260821-0006
CVE-2026-227322026-03-19CRITICAL9.1When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be writt NVD ↗ · NTAP-20260501-0013
CVE-2026-22740——— NVD ↗ · NTAP-20260911-0015
CVE-2026-22741——— NVD ↗ · NTAP-20260911-0016
CVE-2026-22745——— NVD ↗ · NTAP-20260911-0015
CVE-2026-227952026-01-27MEDIUM5.5Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processin NVD ↗ · NTAP-20260204-0005
CVE-2026-227962026-01-27MEDIUM5.3Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without fir NVD ↗ · NTAP-20260204-0004
CVE-2026-22801——— NVD ↗ · NTAP-20260130-0011
CVE-2026-22984——— NVD ↗ · NTAP-20260508-0001
CVE-2026-22988——— NVD ↗ · NTAP-20260305-0017
CVE-2026-229902026-01-23HIGH7.5In the Linux kernel, the following vulnerability has been resolved: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() If the osdmap is (maliciou NVD ↗ · NTAP-20260508-0002
CVE-2026-229912026-01-23HIGH7.5In the Linux kernel, the following vulnerability has been resolved: libceph: make free_choose_arg_map() resilient to partial allocation free_choose_arg_map() ma NVD ↗ · NTAP-20260508-0006
CVE-2026-229922026-01-23HIGH7.5In the Linux kernel, the following vulnerability has been resolved: libceph: return the handler error from mon_handle_auth_done() Currently any error from ceph_ NVD ↗ · NTAP-20260508-0005
CVE-2026-22997——— NVD ↗ · NTAP-20260508-0003
CVE-2026-229982026-01-25HIGH7.5In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec Commit efa56305908b ("n NVD ↗ · NTAP-20260424-0019
CVE-2026-23001——— NVD ↗ · NTAP-20260305-0018
CVE-2026-23003——— NVD ↗ · NTAP-20260508-0004
CVE-2026-23016——— NVD ↗ · NTAP-20260305-0019
CVE-2026-2303——— NVD ↗ · NTAP-20260626-0017
CVE-2026-23066——— NVD ↗ · NTAP-20260911-0019
CVE-2026-23095——— NVD ↗ · NTAP-20260424-0020
CVE-2026-230982026-02-04HIGH8.8In the Linux kernel, the following vulnerability has been resolved: netrom: fix double-free in nr_route_frame() In nr_route_frame(), old_skb is immediately free NVD ↗ · NTAP-20260424-0015
CVE-2026-231122026-02-13CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could NVD ↗ · NTAP-20260424-0013
CVE-2026-23193——— NVD ↗ · NTAP-20260305-0020
CVE-2026-232302026-02-18HIGH8.8In the Linux kernel, the following vulnerability has been resolved: smb: client: split cached_fid bitfields to avoid shared-byte RMW races is_open, has_lease an NVD ↗ · NTAP-20260424-0014
CVE-2026-232312026-03-04HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publis NVD ↗ · NTAP-20260320-0013
CVE-2026-232552026-03-18MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: add proper RCU protection to /proc/net/ptype Yin Fengwei reported an RCU stall in ptype NVD ↗ · NTAP-20260925-0014
CVE-2026-233102026-03-25MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf/bonding: reject vlan+srcmac xmit_hash_policy change when XDP is loaded bond_option_mode_ NVD ↗ · NTAP-20260918-0015
CVE-2026-233892026-03-25MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ice: Fix memory leak in ice_set_ringparam() In ice_set_ringparam, tx_rings and xdp_rings are NVD ↗ · NTAP-20260918-0016
CVE-2026-233992026-03-28MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nf_tables: nft_dynset: fix possible stateful expression memleak in error path If cloning the NVD ↗ · NTAP-20260918-0017
CVE-2026-2340——— NVD ↗ · NTAP-20260527-0006
CVE-2026-234422026-04-03MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipv6: add NULL checks for idev in SRv6 paths __in6_dev_get() can return NULL when the device NVD ↗ · NTAP-20260918-0018
CVE-2026-234442026-04-03HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure ieee80211_tx_prepare_s NVD ↗ · NTAP-20260918-0019
CVE-2026-234682026-04-03MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Userspace can pass an a NVD ↗ · NTAP-20260918-0020
CVE-2026-238652026-03-02MEDIUM5.3An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read o NVD ↗ · NTAP-20260917-0001 · NTAP-20260429-0007
CVE-2026-2391——— NVD ↗ · NTAP-20260515-0010
CVE-2026-23918——— NVD ↗ · NTAP-20260508-0008
CVE-2026-239412026-03-13CRITICAL9.4Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vul NVD ↗ · NTAP-20260703-0005
CVE-2026-239422026-03-13MEDIUM5.4Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. This vulner NVD ↗ · NTAP-20260703-0005
CVE-2026-239432026-03-13MEDIUM5.3Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource Dep NVD ↗ · NTAP-20260703-0005
CVE-2026-239492026-01-20HIGH8.6jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `j NVD ↗ · NTAP-20260327-0011
CVE-2026-23950——— NVD ↗ · NTAP-20260417-0003
CVE-2026-240512026-02-02HIGH7.0OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search NVD ↗ · NTAP-20260917-0001 · NTAP-20260612-0010
CVE-2026-24061——— NVD ↗ · NTAP-20260206-0001
CVE-2026-24072——— NVD ↗ · NTAP-20260508-0013
CVE-2026-24281——— NVD ↗ · NTAP-20260605-0007
CVE-2026-24308——— NVD ↗ · NTAP-20260508-0019
CVE-2026-24733——— NVD ↗ · NTAP-20260227-0002
CVE-2026-24734——— NVD ↗ · NTAP-20260227-0003
CVE-2026-24842——— NVD ↗ · NTAP-20260422-0018
CVE-2026-248802026-04-09HIGH7.5Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects NVD ↗ · NTAP-20260501-0014
CVE-2026-256392026-02-09HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeErro NVD ↗ · NTAP-20260917-0001 · NTAP-20260313-0010
CVE-2026-256462026-02-10HIGH8.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an NVD ↗ · NTAP-20260917-0001
CVE-2026-256792026-03-06HIGH7.5url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. NVD ↗ · NTAP-20260422-0007
CVE-2026-25680——— NVD ↗ · NTAP-20260626-0012
CVE-2026-25681——— NVD ↗ · NTAP-20260626-0012
CVE-2026-25749——— NVD ↗ · NTAP-20260320-0010
CVE-2026-25854——— NVD ↗ · NTAP-20260522-0004
CVE-2026-25896——— NVD ↗ · NTAP-20260311-0006
CVE-2026-260072026-02-10MEDIUM6.5cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or Ellipti NVD ↗ · NTAP-20260917-0001 · NTAP-20260311-0010
CVE-2026-26143——— NVD ↗ · NTAP-20260731-0016
CVE-2026-26157——— NVD ↗ · NTAP-20260305-0006
CVE-2026-26158——— NVD ↗ · NTAP-20260305-0007
CVE-2026-26278——— NVD ↗ · NTAP-20260311-0007
CVE-2026-26732026-03-13MEDIUM6.5Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the NVD ↗ · NTAP-20260320-0015
CVE-2026-269962026-02-20HIGH7.5minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expr NVD ↗ · NTAP-20260917-0001
CVE-2026-270242026-02-20MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop NVD ↗ · NTAP-20260917-0001
CVE-2026-270252026-02-20MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes an NVD ↗ · NTAP-20260917-0001
CVE-2026-270262026-02-20MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. T NVD ↗ · NTAP-20260917-0001
CVE-2026-271352026-03-18HIGH7.5nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data whe NVD ↗ · NTAP-20260717-0011
CVE-2026-27136——— NVD ↗ · NTAP-20260626-0012
CVE-2026-271372026-03-06HIGH7.5When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different do NVD ↗ · NTAP-20260508-0020
CVE-2026-27139——— NVD ↗ · NTAP-20260619-0012
CVE-2026-271402026-04-08HIGH8.8SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass. NVD ↗ · NTAP-20260424-0001
CVE-2026-27141——— NVD ↗ · NTAP-20260320-0012
CVE-2026-271422026-03-06MEDIUM6.1Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with NVD ↗ · NTAP-20260422-0006
CVE-2026-271432026-04-08CRITICAL9.8Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to NVD ↗ · NTAP-20260424-0001
CVE-2026-271442026-04-08HIGH7.1The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct de NVD ↗ · NTAP-20260424-0001
CVE-2026-27145——— NVD ↗ · NTAP-20260619-0006
CVE-2026-27171——— NVD ↗ · NTAP-20260311-0015
CVE-2026-272052026-02-21MEDIUM4.3Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the NVD ↗ · NTAP-20260917-0001
CVE-2026-27446——— NVD ↗ · NTAP-20260320-0011
CVE-2026-27448——— NVD ↗ · NTAP-20260717-0013
CVE-2026-27456——— NVD ↗ · NTAP-20260612-0012
CVE-2026-27699——— NVD ↗ · NTAP-20260424-0008
CVE-2026-279032026-02-26HIGH7.5minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1 NVD ↗ · NTAP-20260917-0001
CVE-2026-279042026-02-26HIGH7.5minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1 NVD ↗ · NTAP-20260917-0001
CVE-2026-28367——— NVD ↗ · NTAP-20260501-0009
CVE-2026-28368——— NVD ↗ · NTAP-20260501-0010
CVE-2026-28369——— NVD ↗ · NTAP-20260501-0011
CVE-2026-28386——— NVD ↗ · NTAP-20260417-0016
CVE-2026-28387——— NVD ↗ · NTAP-20260417-0015
CVE-2026-28388——— NVD ↗ · NTAP-20260417-0014
CVE-2026-28389——— NVD ↗ · NTAP-20260417-0013
CVE-2026-283902026-04-07HIGH7.5Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Ap NVD ↗ · NTAP-20260417-0012
CVE-2026-28780——— NVD ↗ · NTAP-20260508-0007
CVE-2026-28808——— NVD ↗ · NTAP-20260626-0015
CVE-2026-29036——— NVD ↗ · NTAP-20260821-0004
CVE-2026-29145——— NVD ↗ · NTAP-20260522-0003
CVE-2026-291672026-06-08CRITICAL9.8Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67 NVD ↗ · NTAP-20260610-0001
CVE-2026-29168——— NVD ↗ · NTAP-20260508-0011
CVE-2026-29169——— NVD ↗ · NTAP-20260508-0009
CVE-2026-29170——— NVD ↗ · NTAP-20260610-0005
CVE-2026-29181——— NVD ↗ · NTAP-20260513-0010
CVE-2026-29502026-03-31MEDIUM6.5Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://gith NVD ↗ · NTAP-20260917-0001
CVE-2026-29518——— NVD ↗ · NTAP-20260917-0013
CVE-2026-3012——— NVD ↗ · NTAP-20260527-0003
CVE-2026-3039——— NVD ↗ · NTAP-20260529-0001
CVE-2026-309222026-03-18HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recu NVD ↗ · NTAP-20260917-0001
CVE-2026-3104——— NVD ↗ · NTAP-20260403-0004
CVE-2026-3119——— NVD ↗ · NTAP-20260403-0002
CVE-2026-314022026-04-03CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 1 NVD ↗ · NTAP-20260417-0008
CVE-2026-314072026-04-06HIGH7.1In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: add missing netlink policy validations Hyunwoo Kim reports out-of-boun NVD ↗ · NTAP-20260918-0014
CVE-2026-31431——— NVD ↗ · NTAP-20260501-0001
CVE-2026-31589——— NVD ↗ · NTAP-20260814-0001
CVE-2026-31607——— NVD ↗ · NTAP-20260605-0014
CVE-2026-31633——— NVD ↗ · NTAP-20260731-0001
CVE-2026-31718——— NVD ↗ · NTAP-20260703-0001
CVE-2026-31789——— NVD ↗ · NTAP-20260417-0011
CVE-2026-31790——— NVD ↗ · NTAP-20260417-0017
CVE-2026-3184——— NVD ↗ · NTAP-20260612-0011
CVE-2026-319582026-03-11HIGH7.5Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart NVD ↗ · NTAP-20260917-0001
CVE-2026-322802026-04-08HIGH7.5During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Int NVD ↗ · NTAP-20260424-0001
CVE-2026-322812026-04-08HIGH7.5Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, poss NVD ↗ · NTAP-20260424-0001
CVE-2026-322822026-04-08MEDIUM6.4On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even NVD ↗ · NTAP-20260424-0001
CVE-2026-322832026-04-08HIGH7.5If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consum NVD ↗ · NTAP-20260424-0001
CVE-2026-322882026-04-08MEDIUM5.5tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old NVD ↗ · NTAP-20260424-0001
CVE-2026-322892026-04-08MEDIUM6.1Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. A NVD ↗ · NTAP-20260424-0001
CVE-2026-323162026-04-13HIGH8.2jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_string_append() and jvp_string_copy_replace_b NVD ↗ · NTAP-20260918-0001
CVE-2026-3238——— NVD ↗ · NTAP-20260527-0004
CVE-2026-32597——— NVD ↗ · NTAP-20260417-0010
CVE-2026-3260——— NVD ↗ · NTAP-20260403-0015
CVE-2026-32710——— NVD ↗ · NTAP-20260527-0015
CVE-2026-32746——— NVD ↗ · NTAP-20260422-0004
CVE-2026-3276——— NVD ↗ · NTAP-20260731-0013
CVE-2026-32772——— NVD ↗ · NTAP-20260424-0009
CVE-2026-32792——— NVD ↗ · NTAP-20260626-0001
CVE-2026-32990——— NVD ↗ · NTAP-20260522-0005
CVE-2026-33006——— NVD ↗ · NTAP-20260508-0017
CVE-2026-33007——— NVD ↗ · NTAP-20260508-0014
CVE-2026-33056——— NVD ↗ · NTAP-20260422-0017
CVE-2026-331862026-03-20CRITICAL9.1gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 NVD ↗ · NTAP-20260422-0005
CVE-2026-33227——— NVD ↗ · NTAP-20260417-0002
CVE-2026-33228——— NVD ↗ · NTAP-20260501-0008
CVE-2026-332302026-03-20MEDIUM6.1NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Proce NVD ↗ · NTAP-20260917-0001
CVE-2026-332312026-03-20HIGH7.5NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Proce NVD ↗ · NTAP-20260917-0001
CVE-2026-332362026-03-20HIGH8.1NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Proce NVD ↗ · NTAP-20260917-0001
CVE-2026-33278——— NVD ↗ · NTAP-20260626-0001
CVE-2026-33413——— NVD ↗ · NTAP-20260724-0005
CVE-2026-334162026-03-26HIGH7.5LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 th NVD ↗ · NTAP-20260917-0001
CVE-2026-33523——— NVD ↗ · NTAP-20260508-0012
CVE-2026-33630——— NVD ↗ · NTAP-20260731-0015
CVE-2026-33747——— NVD ↗ · NTAP-20260619-0013
CVE-2026-33748——— NVD ↗ · NTAP-20260619-0014
CVE-2026-33810——— NVD ↗ · NTAP-20260424-0003
CVE-2026-33811——— NVD ↗ · NTAP-20260612-0004
CVE-2026-33814——— NVD ↗ · NTAP-20260612-0006
CVE-2026-338452026-04-30HIGH7.5A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and r NVD ↗ · NTAP-20260724-0002
CVE-2026-338462026-05-04HIGH7.5A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incomi NVD ↗ · NTAP-20260724-0002
CVE-2026-33857——— NVD ↗ · NTAP-20260508-0015
CVE-2026-33870——— NVD ↗ · NTAP-20260717-0001 · NTAP-20260626-0008

Years: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2017 · 2016 · 2015 · 2014 · 2013 · 2012 · 2011 · 2010 · 2009 · 2008 · 2007 · 2006 · 2005 · 2004 · 2003 · 2002 · 1999

← CVE index · Security hub