Home / Security / CVE index / 2026
2026 NetApp CVEs (page 2)
Showing 300 CVEs with a 2026 identifier — page 2 of 4. Sorted by CVE id.
Always verify. NetApp's advisory is authoritative for affected versions and fixes; NVD carries the CVSS record.
Showing 300 of 300
| CVE | Published | Severity | CVSS | Summary / Sources |
|---|---|---|---|---|
CVE-2026-33871 | — | — | — | NVD ↗ · NTAP-20260717-0001 · NTAP-20260626-0008 |
CVE-2026-33937 | — | — | — | NVD ↗ · NTAP-20260410-0005 |
CVE-2026-33938 | — | — | — | NVD ↗ · NTAP-20260410-0009 |
CVE-2026-33939 | — | — | — | NVD ↗ · NTAP-20260410-0008 |
CVE-2026-33940 | — | — | — | NVD ↗ · NTAP-20260410-0007 |
CVE-2026-33941 | — | — | — | NVD ↗ · NTAP-20260410-0006 |
CVE-2026-33947 | 2026-04-13 | MEDIUM | 6.2 | jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded NVD ↗ · NTAP-20260918-0005 |
CVE-2026-33948 | 2026-04-14 | MEDIUM | 5.3 | jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation b NVD ↗ · NTAP-20260918-0011 |
CVE-2026-33999 | — | — | — | NVD ↗ · NTAP-20260610-0008 |
CVE-2026-34000 | — | — | — | NVD ↗ · NTAP-20260610-0006 |
CVE-2026-34001 | — | — | — | NVD ↗ · NTAP-20260610-0009 |
CVE-2026-34002 | — | — | — | NVD ↗ · NTAP-20260610-0007 |
CVE-2026-34003 | — | — | — | NVD ↗ · NTAP-20260610-0010 |
CVE-2026-34032 | — | — | — | NVD ↗ · NTAP-20260508-0016 |
CVE-2026-34059 | — | — | — | NVD ↗ · NTAP-20260508-0010 |
CVE-2026-34073 | 2026-03-31 | MEDIUM | 5.3 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only NVD ↗ · NTAP-20260917-0001 |
CVE-2026-34180 | 2026-06-09 | HIGH | 7.5 | Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-r NVD ↗ · NTAP-20260617-0009 |
CVE-2026-34181 | 2026-06-09 | HIGH | 7.4 | Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) NVD ↗ · NTAP-20260617-0010 |
CVE-2026-34182 | 2026-06-09 | CRITICAL | 9.1 | Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnveloped NVD ↗ · NTAP-20260617-0001 |
CVE-2026-34183 | 2026-06-09 | HIGH | 7.5 | Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A NVD ↗ · NTAP-20260617-0006 |
CVE-2026-34197 | — | — | — | NVD ↗ · NTAP-20260417-0001 |
CVE-2026-34267 | — | — | — | NVD ↗ · NTAP-20260429-0004 |
CVE-2026-34268 | 2026-04-21 | LOW | 2.9 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versio NVD ↗ · NTAP-20260917-0001 · NTAP-20260429-0012 |
CVE-2026-34270 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-34271 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-34272 | — | — | — | NVD ↗ · NTAP-20260429-0006 |
CVE-2026-34276 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-34278 | — | — | — | NVD ↗ · NTAP-20260429-0004 |
CVE-2026-34282 | 2026-04-21 | HIGH | 7.5 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported vers NVD ↗ · NTAP-20260917-0001 · NTAP-20260429-0011 |
CVE-2026-34293 | — | — | — | NVD ↗ · NTAP-20260429-0004 |
CVE-2026-34303 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-34304 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-34308 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-34317 | 2026-04-21 | MEDIUM | 5.0 | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and NVD ↗ · NTAP-20260925-0029 |
CVE-2026-34318 | 2026-04-21 | MEDIUM | 5.8 | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and NVD ↗ · NTAP-20260925-0028 |
CVE-2026-34319 | 2026-04-21 | MEDIUM | 5.0 | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and NVD ↗ · NTAP-20260925-0030 |
CVE-2026-34355 | 2026-06-08 | HIGH | 7.5 | A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to versi NVD ↗ · NTAP-20260610-0001 |
CVE-2026-34356 | 2026-06-08 | HIGH | 7.5 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: NVD ↗ · NTAP-20260610-0001 |
CVE-2026-34477 | — | — | — | NVD ↗ · NTAP-20260626-0009 · NTAP-20260513-0008 |
CVE-2026-34478 | — | — | — | NVD ↗ · NTAP-20260710-0002 · NTAP-20260626-0009 |
CVE-2026-34479 | — | — | — | NVD ↗ · NTAP-20260717-0007 · NTAP-20260703-0011 |
CVE-2026-34480 | — | — | — | NVD ↗ · NTAP-20260626-0009 · NTAP-20260513-0007 |
CVE-2026-34481 | — | — | — | NVD ↗ · NTAP-20260703-0012 |
CVE-2026-34483 | — | — | — | NVD ↗ · NTAP-20260522-0008 |
CVE-2026-34486 | — | — | — | NVD ↗ · NTAP-20260522-0009 |
CVE-2026-34487 | — | — | — | NVD ↗ · NTAP-20260522-0007 |
CVE-2026-34500 | — | — | — | NVD ↗ · NTAP-20260522-0006 |
CVE-2026-34986 | — | — | — | NVD ↗ · NTAP-20260617-0020 |
CVE-2026-35188 | 2026-06-09 | MEDIUM | 5.0 | Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free NVD ↗ · NTAP-20260617-0015 |
CVE-2026-35234 | — | — | — | NVD ↗ · NTAP-20260429-0006 |
CVE-2026-35235 | — | — | — | NVD ↗ · NTAP-20260429-0006 |
CVE-2026-35236 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-35237 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-35238 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-35239 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-35240 | — | — | — | NVD ↗ · NTAP-20260429-0005 |
CVE-2026-35385 | 2026-04-02 | HIGH | 7.5 | In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performe NVD ↗ · NTAP-20260417-0018 |
CVE-2026-35386 | — | — | — | NVD ↗ · NTAP-20260424-0004 |
CVE-2026-35387 | — | — | — | NVD ↗ · NTAP-20260424-0005 |
CVE-2026-35388 | — | — | — | NVD ↗ · NTAP-20260424-0006 |
CVE-2026-35414 | 2026-04-02 | MEDIUM | 4.2 | OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authori NVD ↗ · NTAP-20260417-0019 |
CVE-2026-35469 | — | — | — | NVD ↗ · NTAP-20260513-0009 |
CVE-2026-35536 | 2026-04-03 | HIGH | 7.2 | In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked NVD ↗ · NTAP-20260917-0001 |
CVE-2026-35547 | 2026-04-30 | HIGH | 8.1 | When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to writ NVD ↗ · NTAP-20260501-0002 |
CVE-2026-35554 | — | — | — | NVD ↗ · NTAP-20260605-0008 |
CVE-2026-3591 | — | — | — | NVD ↗ · NTAP-20260403-0001 |
CVE-2026-3592 | — | — | — | NVD ↗ · NTAP-20260529-0005 |
CVE-2026-3593 | — | — | — | NVD ↗ · NTAP-20260529-0004 |
CVE-2026-3644 | — | — | — | NVD ↗ · NTAP-20260410-0020 |
CVE-2026-3676 | — | — | — | NVD ↗ · NTAP-20260422-0008 |
CVE-2026-3713 | 2026-03-08 | MEDIUM | 5.3 | A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the c NVD ↗ · NTAP-20260917-0001 |
CVE-2026-3783 | 2026-03-11 | MEDIUM | 5.3 | When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hos NVD ↗ · NTAP-20260327-0004 |
CVE-2026-3784 | 2026-03-11 | MEDIUM | 6.5 | curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The NVD ↗ · NTAP-20260327-0003 |
CVE-2026-3805 | 2026-03-11 | HIGH | 7.5 | When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory. NVD ↗ · NTAP-20260327-0001 |
CVE-2026-3833 | 2026-04-30 | MEDIUM | 6.5 | A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` NVD ↗ · NTAP-20260724-0002 |
CVE-2026-3904 | — | — | — | NVD ↗ · NTAP-20260410-0018 |
CVE-2026-39457 | — | — | — | NVD ↗ · NTAP-20260501-0004 |
CVE-2026-39461 | — | — | — | NVD ↗ · NTAP-20260527-0007 |
CVE-2026-39817 | — | — | — | NVD ↗ · NTAP-20260619-0009 |
CVE-2026-39819 | — | — | — | NVD ↗ · NTAP-20260619-0010 |
CVE-2026-39820 | — | — | — | NVD ↗ · NTAP-20260612-0005 |
CVE-2026-39821 | — | — | — | NVD ↗ · NTAP-20260626-0012 |
CVE-2026-39822 | — | — | — | NVD ↗ · NTAP-20260731-0009 |
CVE-2026-39823 | — | — | — | NVD ↗ · NTAP-20260619-0008 |
CVE-2026-39824 | — | — | — | NVD ↗ · NTAP-20260917-0001 · NTAP-20260612-0007 |
CVE-2026-39825 | — | — | — | NVD ↗ · NTAP-20260619-0011 |
CVE-2026-39826 | — | — | — | NVD ↗ · NTAP-20260619-0007 |
CVE-2026-39827 | — | — | — | NVD ↗ · NTAP-20260626-0013 |
CVE-2026-39828 | — | — | — | NVD ↗ · NTAP-20260617-0019 |
CVE-2026-39829 | — | — | — | NVD ↗ · NTAP-20260617-0019 |
CVE-2026-39830 | — | — | — | NVD ↗ · NTAP-20260617-0019 |
CVE-2026-39831 | — | — | — | NVD ↗ · NTAP-20260617-0019 |
CVE-2026-39832 | — | — | — | NVD ↗ · NTAP-20260617-0019 |
CVE-2026-39833 | — | — | — | NVD ↗ · NTAP-20260617-0019 |
CVE-2026-39834 | — | — | — | NVD ↗ · NTAP-20260617-0019 |
CVE-2026-39835 | — | — | — | NVD ↗ · NTAP-20260617-0019 |
CVE-2026-39836 | — | — | — | NVD ↗ · NTAP-20260619-0005 |
CVE-2026-39865 | — | — | — | NVD ↗ · NTAP-20260422-0002 |
CVE-2026-39882 | — | — | — | NVD ↗ · NTAP-20260612-0009 |
CVE-2026-39883 | — | — | — | NVD ↗ · NTAP-20260612-0008 |
CVE-2026-39892 | 2026-04-08 | CRITICAL | 9.8 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer NVD ↗ · NTAP-20260917-0001 |
CVE-2026-39956 | 2026-04-13 | MEDIUM | 6.1 | jq is a command-line JSON processor. Prior to version 1.8.2, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() NVD ↗ · NTAP-20260918-0008 |
CVE-2026-39979 | 2026-04-13 | MEDIUM | 6.5 | jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with NVD ↗ · NTAP-20260918-0003 |
CVE-2026-40021 | — | — | — | NVD ↗ · NTAP-20260522-0002 |
CVE-2026-40023 | — | — | — | NVD ↗ · NTAP-20260710-0003 |
CVE-2026-40164 | 2026-04-14 | HIGH | 7.5 | jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A NVD ↗ · NTAP-20260918-0002 |
CVE-2026-40175 | — | — | — | NVD ↗ · NTAP-20260917-0001 · NTAP-20260417-0020 |
CVE-2026-40179 | 2026-04-15 | MEDIUM | 6.1 | Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vu NVD ↗ · NTAP-20260930-0017 |
CVE-2026-40192 | 2026-04-15 | HIGH | 7.5 | Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them NVD ↗ · NTAP-20260917-0001 |
CVE-2026-40355 | — | — | — | NVD ↗ · NTAP-20260911-0018 |
CVE-2026-40356 | — | — | — | NVD ↗ · NTAP-20260911-0018 |
CVE-2026-40372 | — | — | — | NVD ↗ · NTAP-20260429-0003 |
CVE-2026-4046 | 2026-03-30 | HIGH | 7.5 | The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 cha NVD ↗ · NTAP-20260422-0003 |
CVE-2026-40466 | 2026-04-24 | HIGH | 8.8 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache Active NVD ↗ · NTAP-20260917-0001 |
CVE-2026-40622 | — | — | — | NVD ↗ · NTAP-20260626-0001 |
CVE-2026-40682 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-40701 | — | — | — | NVD ↗ · NTAP-20260522-0013 |
CVE-2026-40864 | 2026-05-22 | MEDIUM | 5.4 | JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0 NVD ↗ · NTAP-20260917-0001 |
CVE-2026-40971 | — | — | — | NVD ↗ · NTAP-20260626-0018 |
CVE-2026-40972 | — | — | — | NVD ↗ · NTAP-20260605-0013 |
CVE-2026-40973 | — | — | — | NVD ↗ · NTAP-20260605-0013 |
CVE-2026-40974 | — | — | — | NVD ↗ · NTAP-20260605-0013 |
CVE-2026-40975 | — | — | — | NVD ↗ · NTAP-20260605-0013 |
CVE-2026-40976 | — | — | — | NVD ↗ · NTAP-20260821-0005 |
CVE-2026-40977 | — | — | — | NVD ↗ · NTAP-20260605-0009 |
CVE-2026-40993 | — | — | — | NVD ↗ · NTAP-20260731-0011 |
CVE-2026-41044 | 2026-04-24 | HIGH | 8.8 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ A NVD ↗ · NTAP-20260917-0001 |
CVE-2026-41254 | — | — | — | NVD ↗ · NTAP-20260724-0015 |
CVE-2026-41256 | 2026-05-11 | MEDIUM | 5.5 | jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on curr NVD ↗ · NTAP-20260918-0009 |
CVE-2026-41257 | 2026-05-11 | MEDIUM | 5.5 | jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyo NVD ↗ · NTAP-20260918-0004 |
CVE-2026-41284 | — | — | — | NVD ↗ · NTAP-20260529-0014 |
CVE-2026-41292 | — | — | — | NVD ↗ · NTAP-20260626-0001 |
CVE-2026-41293 | — | — | — | NVD ↗ · NTAP-20260529-0014 |
CVE-2026-41417 | 2026-05-06 | MEDIUM | 5.3 | Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `s NVD ↗ · NTAP-20260917-0001 · NTAP-20260717-0004 +1 |
CVE-2026-41586 | 2026-05-07 | CRITICAL | 9.8 | Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Ch NVD ↗ · NTAP-20260917-0002 |
CVE-2026-41602 | — | — | — | NVD ↗ · NTAP-20260529-0015 |
CVE-2026-41603 | — | — | — | NVD ↗ · NTAP-20260529-0015 |
CVE-2026-41604 | — | — | — | NVD ↗ · NTAP-20260529-0015 |
CVE-2026-41605 | — | — | — | NVD ↗ · NTAP-20260529-0015 |
CVE-2026-41606 | — | — | — | NVD ↗ · NTAP-20260529-0015 |
CVE-2026-41607 | — | — | — | NVD ↗ · NTAP-20260529-0015 |
CVE-2026-41636 | — | — | — | NVD ↗ · NTAP-20260529-0015 |
CVE-2026-41838 | 2026-06-09 | MEDIUM | 4.8 | IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequa NVD ↗ · NTAP-20260924-0007 |
CVE-2026-41839 | — | — | — | NVD ↗ · NTAP-20260731-0014 |
CVE-2026-41840 | 2026-06-09 | MEDIUM | 5.9 | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 thro NVD ↗ · NTAP-20260924-0007 |
CVE-2026-41841 | 2026-06-09 | MEDIUM | 5.9 | Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 NVD ↗ · NTAP-20260924-0007 |
CVE-2026-41842 | 2026-06-09 | HIGH | 7.5 | Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 NVD ↗ · NTAP-20260924-0007 |
CVE-2026-41843 | 2026-06-09 | MEDIUM | 5.9 | Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through NVD ↗ · NTAP-20260924-0007 |
CVE-2026-41844 | 2026-06-09 | MEDIUM | 4.2 | A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a li NVD ↗ · NTAP-20260924-0007 |
CVE-2026-41845 | 2026-06-09 | HIGH | 7.1 | Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross- NVD ↗ · NTAP-20260924-0007 |
CVE-2026-41846 | 2026-06-09 | MEDIUM | 5.9 | Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScrip NVD ↗ · NTAP-20260924-0007 |
CVE-2026-41847 | 2026-06-09 | MEDIUM | 4.8 | Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48. NVD ↗ · NTAP-20260924-0010 |
CVE-2026-41848 | 2026-06-09 | LOW | 3.7 | Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or in NVD ↗ · NTAP-20260924-0007 |
CVE-2026-41849 | 2026-06-09 | HIGH | 7.5 | An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially NVD ↗ · NTAP-20260924-0004 |
CVE-2026-41850 | 2026-06-09 | HIGH | 7.5 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a NVD ↗ · NTAP-20260924-0007 |
CVE-2026-41851 | 2026-06-09 | MEDIUM | 5.3 | Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of NVD ↗ · NTAP-20260924-0007 |
CVE-2026-41852 | 2026-06-09 | LOW | 3.7 | A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only NVD ↗ · NTAP-20260924-0007 |
CVE-2026-41853 | 2026-06-09 | MEDIUM | 5.3 | Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 throug NVD ↗ · NTAP-20260924-0007 |
CVE-2026-41854 | — | — | — | NVD ↗ · NTAP-20260717-0017 |
CVE-2026-41855 | — | — | — | NVD ↗ · NTAP-20260911-0014 |
CVE-2026-41989 | — | — | — | NVD ↗ · NTAP-20260917-0019 |
CVE-2026-42027 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42033 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42034 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42035 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42036 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42037 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42038 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42039 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42040 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42041 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42042 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42043 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42044 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42151 | 2026-05-04 | HIGH | 7.5 | Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote writ NVD ↗ · NTAP-20260930-0018 |
CVE-2026-42154 | 2026-05-04 | HIGH | 7.5 | Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not va NVD ↗ · NTAP-20260930-0019 |
CVE-2026-42198 | 2026-04-29 | HIGH | 7.5 | pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during S NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42253 | — | — | — | NVD ↗ · NTAP-20260710-0001 |
CVE-2026-42264 | 2026-05-08 | HIGH | 7.4 | Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPat NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42402 | 2026-05-01 | HIGH | 7.5 | Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trig NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42403 | 2026-05-01 | HIGH | 7.5 | Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42404 | 2026-05-01 | MEDIUM | 6.5 | Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application expl NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42440 | — | — | — | NVD ↗ · NTAP-20260917-0001 |
CVE-2026-4247 | — | — | — | NVD ↗ · NTAP-20260417-0005 |
CVE-2026-42496 | — | — | — | NVD ↗ · NTAP-20260911-0013 |
CVE-2026-42498 | — | — | — | NVD ↗ · NTAP-20260522-0010 |
CVE-2026-42499 | — | — | — | NVD ↗ · NTAP-20260619-0003 |
CVE-2026-42501 | — | — | — | NVD ↗ · NTAP-20260619-0004 |
CVE-2026-42502 | — | — | — | NVD ↗ · NTAP-20260626-0012 |
CVE-2026-42504 | — | — | — | NVD ↗ · NTAP-20260619-0002 |
CVE-2026-42505 | — | — | — | NVD ↗ · NTAP-20260731-0010 |
CVE-2026-42506 | — | — | — | NVD ↗ · NTAP-20260626-0012 |
CVE-2026-42508 | — | — | — | NVD ↗ · NTAP-20260617-0019 |
CVE-2026-42511 | 2026-04-30 | HIGH | 8.1 | The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the le NVD ↗ · NTAP-20260501-0005 |
CVE-2026-42512 | 2026-04-30 | HIGH | 8.1 | As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrec NVD ↗ · NTAP-20260501-0006 |
CVE-2026-42533 | — | — | — | NVD ↗ · NTAP-20260724-0001 |
CVE-2026-42534 | — | — | — | NVD ↗ · NTAP-20260626-0001 |
CVE-2026-42535 | — | — | — | NVD ↗ · NTAP-20260610-0002 |
CVE-2026-42536 | 2026-06-08 | HIGH | 7.5 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: fr NVD ↗ · NTAP-20260610-0001 |
CVE-2026-42577 | 2026-05-13 | HIGH | 7.5 | Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP c NVD ↗ · NTAP-20260917-0001 |
CVE-2026-42578 | 2026-05-13 | HIGH | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 |
CVE-2026-42579 | — | — | — | NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 |
CVE-2026-42580 | 2026-05-13 | MEDIUM | 6.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 +1 |
CVE-2026-42581 | 2026-05-13 | MEDIUM | 5.8 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Le NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 +1 |
CVE-2026-42583 | 2026-05-13 | HIGH | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decom NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 +1 |
CVE-2026-42584 | 2026-05-13 | HIGH | 7.3 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 +1 |
CVE-2026-42585 | 2026-05-13 | MEDIUM | 6.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encod NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 +1 |
CVE-2026-42586 | — | — | — | NVD ↗ · NTAP-20260626-0019 |
CVE-2026-42587 | 2026-05-13 | HIGH | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation p NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 +1 |
CVE-2026-42588 | — | — | — | NVD ↗ · NTAP-20260710-0001 |
CVE-2026-42764 | 2026-06-09 | HIGH | 7.5 | Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation d NVD ↗ · NTAP-20260617-0004 |
CVE-2026-42765 | 2026-06-09 | HIGH | 7.5 | Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen NVD ↗ · NTAP-20260617-0005 |
CVE-2026-42766 | 2026-06-09 | MEDIUM | 5.9 | Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointe NVD ↗ · NTAP-20260617-0013 |
CVE-2026-42767 | 2026-06-09 | MEDIUM | 5.9 | Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact NVD ↗ · NTAP-20260617-0012 |
CVE-2026-42768 | 2026-06-09 | LOW | 3.7 | Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME m NVD ↗ · NTAP-20260617-0017 |
CVE-2026-42769 | 2026-06-09 | MEDIUM | 5.3 | Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response r NVD ↗ · NTAP-20260617-0014 |
CVE-2026-42770 | 2026-06-09 | LOW | 3.7 | Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact s NVD ↗ · NTAP-20260617-0018 |
CVE-2026-42771 | 2026-06-09 | MEDIUM | 6.2 | Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, NVD ↗ · NTAP-20260617-0011 |
CVE-2026-42790 | 2026-05-27 | HIGH | 8.1 | Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject Comm NVD ↗ · NTAP-20260605-0010 |
CVE-2026-42923 | — | — | — | NVD ↗ · NTAP-20260626-0001 |
CVE-2026-42934 | — | — | — | NVD ↗ · NTAP-20260522-0014 |
CVE-2026-42944 | — | — | — | NVD ↗ · NTAP-20260626-0001 |
CVE-2026-42945 | — | — | — | NVD ↗ · NTAP-20260522-0011 |
CVE-2026-42946 | — | — | — | NVD ↗ · NTAP-20260522-0012 |
CVE-2026-42959 | — | — | — | NVD ↗ · NTAP-20260626-0001 |
CVE-2026-42960 | — | — | — | NVD ↗ · NTAP-20260626-0001 |
CVE-2026-43284 | — | — | — | NVD ↗ · NTAP-20260513-0001 |
CVE-2026-43499 | — | — | — | NVD ↗ · NTAP-20260710-0018 |
CVE-2026-43500 | — | — | — | NVD ↗ · NTAP-20260513-0002 |
CVE-2026-43501 | — | — | — | NVD ↗ · NTAP-20260605-0015 |
CVE-2026-43503 | — | — | — | NVD ↗ · NTAP-20260710-0019 |
CVE-2026-43512 | — | — | — | NVD ↗ · NTAP-20260529-0014 |
CVE-2026-43513 | — | — | — | NVD ↗ · NTAP-20260529-0014 |
CVE-2026-43514 | — | — | — | NVD ↗ · NTAP-20260529-0014 |
CVE-2026-43515 | — | — | — | NVD ↗ · NTAP-20260529-0014 |
CVE-2026-43617 | — | — | — | NVD ↗ · NTAP-20260917-0016 |
CVE-2026-43618 | — | — | — | NVD ↗ · NTAP-20260917-0017 |
CVE-2026-43619 | — | — | — | NVD ↗ · NTAP-20260917-0014 |
CVE-2026-43620 | — | — | — | NVD ↗ · NTAP-20260917-0015 |
CVE-2026-43868 | — | — | — | NVD ↗ · NTAP-20260529-0015 |
CVE-2026-43869 | 2026-05-05 | HIGH | 7.3 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to NVD ↗ · NTAP-20260917-0001 · NTAP-20260529-0015 |
CVE-2026-43870 | — | — | — | NVD ↗ · NTAP-20260529-0015 |
CVE-2026-43894 | 2026-05-11 | MEDIUM | 6.2 | jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro NVD ↗ · NTAP-20260918-0006 |
CVE-2026-43895 | 2026-05-11 | MEDIUM | 4.4 | jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those path NVD ↗ · NTAP-20260918-0012 |
CVE-2026-43896 | 2026-05-11 | MEDIUM | 6.2 | jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process w NVD ↗ · NTAP-20260918-0007 |
CVE-2026-43951 | 2026-06-08 | MEDIUM | 6.5 | Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: fro NVD ↗ · NTAP-20260610-0001 |
CVE-2026-4408 | — | — | — | NVD ↗ · NTAP-20260527-0001 |
CVE-2026-44119 | 2026-06-08 | MEDIUM | 5.5 | Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the htt NVD ↗ · NTAP-20260610-0001 |
CVE-2026-44170 | — | — | — | NVD ↗ · NTAP-20260828-0019 |
CVE-2026-44185 | 2026-06-08 | HIGH | 7.3 | Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: fro NVD ↗ · NTAP-20260610-0001 |
CVE-2026-44186 | 2026-06-08 | HIGH | 7.3 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP s NVD ↗ · NTAP-20260610-0001 |
CVE-2026-44248 | — | — | — | NVD ↗ · NTAP-20260626-0019 |
CVE-2026-44249 | 2026-06-11 | HIGH | 8.1 | Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an NVD ↗ · NTAP-20260917-0005 · NTAP-20260626-0020 |
CVE-2026-44250 | — | — | — | NVD ↗ · NTAP-20260626-0020 |
CVE-2026-4426 | — | — | — | NVD ↗ · NTAP-20260417-0007 |
CVE-2026-4437 | — | — | — | NVD ↗ · NTAP-20260410-0017 |
CVE-2026-4438 | — | — | — | NVD ↗ · NTAP-20260410-0017 |
CVE-2026-44390 | — | — | — | NVD ↗ · NTAP-20260626-0001 |
CVE-2026-44417 | — | — | — | NVD ↗ · NTAP-20260618-0002 |
CVE-2026-44431 | 2026-05-13 | MEDIUM | 5.3 | urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from NVD ↗ · NTAP-20260917-0001 · NTAP-20260724-0004 |
CVE-2026-44432 | — | — | — | NVD ↗ · NTAP-20260917-0001 · NTAP-20260724-0003 |
CVE-2026-44578 | — | — | — | NVD ↗ · NTAP-20260529-0013 |
CVE-2026-44604 | — | — | — | NVD ↗ · NTAP-20260828-0018 |
CVE-2026-44608 | — | — | — | NVD ↗ · NTAP-20260626-0001 |
CVE-2026-44618 | — | — | — | NVD ↗ · NTAP-20260618-0003 |
CVE-2026-44631 | 2026-06-08 | CRITICAL | 9.8 | Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 thr NVD ↗ · NTAP-20260610-0001 |
CVE-2026-44777 | 2026-05-11 | MEDIUM | 5.5 | jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules inclu NVD ↗ · NTAP-20260918-0010 |
CVE-2026-4480 | — | — | — | NVD ↗ · NTAP-20260527-0002 |
CVE-2026-44890 | — | — | — | NVD ↗ · NTAP-20260626-0020 |
CVE-2026-44892 | — | — | — | NVD ↗ · NTAP-20260724-0013 |
CVE-2026-44893 | — | — | — | NVD ↗ · NTAP-20260626-0020 |
CVE-2026-44894 | — | — | — | NVD ↗ · NTAP-20260724-0013 |
CVE-2026-44903 | 2026-05-26 | MEDIUM | 6.1 | Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabl NVD ↗ · NTAP-20260930-0020 |
CVE-2026-44930 | — | — | — | NVD ↗ · NTAP-20260618-0001 |
CVE-2026-4519 | — | — | — | NVD ↗ · NTAP-20260410-0019 |
CVE-2026-45205 | 2026-05-14 | MEDIUM | 5.3 | Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError f NVD ↗ · NTAP-20260917-0001 · NTAP-20260814-0010 |
CVE-2026-45232 | — | — | — | NVD ↗ · NTAP-20260917-0018 |
CVE-2026-45250 | — | — | — | NVD ↗ · NTAP-20260527-0009 |
CVE-2026-45251 | — | — | — | NVD ↗ · NTAP-20260527-0010 |
CVE-2026-45252 | — | — | — | NVD ↗ · NTAP-20260527-0013 |
CVE-2026-45253 | — | — | — | NVD ↗ · NTAP-20260527-0008 |
CVE-2026-45254 | — | — | — | NVD ↗ · NTAP-20260527-0012 |
CVE-2026-45255 | — | — | — | NVD ↗ · NTAP-20260527-0011 |
CVE-2026-45256 | — | — | — | NVD ↗ · NTAP-20260626-0004 |
CVE-2026-45257 | — | — | — | NVD ↗ · NTAP-20260619-0020 |
CVE-2026-45258 | — | — | — | NVD ↗ · NTAP-20260626-0002 |
CVE-2026-45259 | — | — | — | NVD ↗ · NTAP-20260626-0005 |
CVE-2026-45292 | — | — | — | NVD ↗ · NTAP-20260828-0020 |
CVE-2026-4539 | 2026-03-22 | LOW | 3.3 | A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipu NVD ↗ · NTAP-20260917-0001 |
CVE-2026-45416 | — | — | — | NVD ↗ · NTAP-20260626-0020 |
CVE-2026-45445 | 2026-06-09 | HIGH | 7.5 | Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector NVD ↗ · NTAP-20260617-0007 |
CVE-2026-45446 | 2026-06-09 | MEDIUM | 4.8 | Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an NVD ↗ · NTAP-20260617-0016 |
CVE-2026-45447 | 2026-06-09 | HIGH | 8.8 | Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-af NVD ↗ · NTAP-20260617-0002 |
CVE-2026-45490 | — | — | — | NVD ↗ · NTAP-20260703-0008 |
CVE-2026-45491 | — | — | — | NVD ↗ · NTAP-20260703-0009 |
CVE-2026-45505 | — | — | — | NVD ↗ · NTAP-20260710-0001 |
CVE-2026-45536 | 2026-06-12 | MEDIUM | 4.0 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_re NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0020 |
CVE-2026-45591 | — | — | — | NVD ↗ · NTAP-20260703-0010 |
CVE-2026-45673 | — | — | — | NVD ↗ · NTAP-20260626-0020 |
CVE-2026-45674 | — | — | — | NVD ↗ · NTAP-20260626-0020 |
Years: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2017 · 2016 · 2015 · 2014 · 2013 · 2012 · 2011 · 2010 · 2009 · 2008 · 2007 · 2006 · 2005 · 2004 · 2003 · 2002 · 1999