Home / Security / CVE index / 2026

2026 NetApp CVEs (page 2)

Showing 300 CVEs with a 2026 identifier — page 2 of 4. Sorted by CVE id.

Always verify. NetApp's advisory is authoritative for affected versions and fixes; NVD carries the CVSS record.
Showing 300 of 300
CVEPublishedSeverityCVSSSummary / Sources
CVE-2026-33871——— NVD ↗ · NTAP-20260717-0001 · NTAP-20260626-0008
CVE-2026-33937——— NVD ↗ · NTAP-20260410-0005
CVE-2026-33938——— NVD ↗ · NTAP-20260410-0009
CVE-2026-33939——— NVD ↗ · NTAP-20260410-0008
CVE-2026-33940——— NVD ↗ · NTAP-20260410-0007
CVE-2026-33941——— NVD ↗ · NTAP-20260410-0006
CVE-2026-339472026-04-13MEDIUM6.2jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded NVD ↗ · NTAP-20260918-0005
CVE-2026-339482026-04-14MEDIUM5.3jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation b NVD ↗ · NTAP-20260918-0011
CVE-2026-33999——— NVD ↗ · NTAP-20260610-0008
CVE-2026-34000——— NVD ↗ · NTAP-20260610-0006
CVE-2026-34001——— NVD ↗ · NTAP-20260610-0009
CVE-2026-34002——— NVD ↗ · NTAP-20260610-0007
CVE-2026-34003——— NVD ↗ · NTAP-20260610-0010
CVE-2026-34032——— NVD ↗ · NTAP-20260508-0016
CVE-2026-34059——— NVD ↗ · NTAP-20260508-0010
CVE-2026-340732026-03-31MEDIUM5.3cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only NVD ↗ · NTAP-20260917-0001
CVE-2026-341802026-06-09HIGH7.5Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-r NVD ↗ · NTAP-20260617-0009
CVE-2026-341812026-06-09HIGH7.4Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) NVD ↗ · NTAP-20260617-0010
CVE-2026-341822026-06-09CRITICAL9.1Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnveloped NVD ↗ · NTAP-20260617-0001
CVE-2026-341832026-06-09HIGH7.5Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A NVD ↗ · NTAP-20260617-0006
CVE-2026-34197——— NVD ↗ · NTAP-20260417-0001
CVE-2026-34267——— NVD ↗ · NTAP-20260429-0004
CVE-2026-342682026-04-21LOW2.9Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versio NVD ↗ · NTAP-20260917-0001 · NTAP-20260429-0012
CVE-2026-34270——— NVD ↗ · NTAP-20260429-0005
CVE-2026-34271——— NVD ↗ · NTAP-20260429-0005
CVE-2026-34272——— NVD ↗ · NTAP-20260429-0006
CVE-2026-34276——— NVD ↗ · NTAP-20260429-0005
CVE-2026-34278——— NVD ↗ · NTAP-20260429-0004
CVE-2026-342822026-04-21HIGH7.5Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported vers NVD ↗ · NTAP-20260917-0001 · NTAP-20260429-0011
CVE-2026-34293——— NVD ↗ · NTAP-20260429-0004
CVE-2026-34303——— NVD ↗ · NTAP-20260429-0005
CVE-2026-34304——— NVD ↗ · NTAP-20260429-0005
CVE-2026-34308——— NVD ↗ · NTAP-20260429-0005
CVE-2026-343172026-04-21MEDIUM5.0Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and NVD ↗ · NTAP-20260925-0029
CVE-2026-343182026-04-21MEDIUM5.8Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and NVD ↗ · NTAP-20260925-0028
CVE-2026-343192026-04-21MEDIUM5.0Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and NVD ↗ · NTAP-20260925-0030
CVE-2026-343552026-06-08HIGH7.5A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to versi NVD ↗ · NTAP-20260610-0001
CVE-2026-343562026-06-08HIGH7.5Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: NVD ↗ · NTAP-20260610-0001
CVE-2026-34477——— NVD ↗ · NTAP-20260626-0009 · NTAP-20260513-0008
CVE-2026-34478——— NVD ↗ · NTAP-20260710-0002 · NTAP-20260626-0009
CVE-2026-34479——— NVD ↗ · NTAP-20260717-0007 · NTAP-20260703-0011
CVE-2026-34480——— NVD ↗ · NTAP-20260626-0009 · NTAP-20260513-0007
CVE-2026-34481——— NVD ↗ · NTAP-20260703-0012
CVE-2026-34483——— NVD ↗ · NTAP-20260522-0008
CVE-2026-34486——— NVD ↗ · NTAP-20260522-0009
CVE-2026-34487——— NVD ↗ · NTAP-20260522-0007
CVE-2026-34500——— NVD ↗ · NTAP-20260522-0006
CVE-2026-34986——— NVD ↗ · NTAP-20260617-0020
CVE-2026-351882026-06-09MEDIUM5.0Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free NVD ↗ · NTAP-20260617-0015
CVE-2026-35234——— NVD ↗ · NTAP-20260429-0006
CVE-2026-35235——— NVD ↗ · NTAP-20260429-0006
CVE-2026-35236——— NVD ↗ · NTAP-20260429-0005
CVE-2026-35237——— NVD ↗ · NTAP-20260429-0005
CVE-2026-35238——— NVD ↗ · NTAP-20260429-0005
CVE-2026-35239——— NVD ↗ · NTAP-20260429-0005
CVE-2026-35240——— NVD ↗ · NTAP-20260429-0005
CVE-2026-353852026-04-02HIGH7.5In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performe NVD ↗ · NTAP-20260417-0018
CVE-2026-35386——— NVD ↗ · NTAP-20260424-0004
CVE-2026-35387——— NVD ↗ · NTAP-20260424-0005
CVE-2026-35388——— NVD ↗ · NTAP-20260424-0006
CVE-2026-354142026-04-02MEDIUM4.2OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authori NVD ↗ · NTAP-20260417-0019
CVE-2026-35469——— NVD ↗ · NTAP-20260513-0009
CVE-2026-355362026-04-03HIGH7.2In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked NVD ↗ · NTAP-20260917-0001
CVE-2026-355472026-04-30HIGH8.1When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to writ NVD ↗ · NTAP-20260501-0002
CVE-2026-35554——— NVD ↗ · NTAP-20260605-0008
CVE-2026-3591——— NVD ↗ · NTAP-20260403-0001
CVE-2026-3592——— NVD ↗ · NTAP-20260529-0005
CVE-2026-3593——— NVD ↗ · NTAP-20260529-0004
CVE-2026-3644——— NVD ↗ · NTAP-20260410-0020
CVE-2026-3676——— NVD ↗ · NTAP-20260422-0008
CVE-2026-37132026-03-08MEDIUM5.3A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the c NVD ↗ · NTAP-20260917-0001
CVE-2026-37832026-03-11MEDIUM5.3When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hos NVD ↗ · NTAP-20260327-0004
CVE-2026-37842026-03-11MEDIUM6.5curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The NVD ↗ · NTAP-20260327-0003
CVE-2026-38052026-03-11HIGH7.5When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory. NVD ↗ · NTAP-20260327-0001
CVE-2026-38332026-04-30MEDIUM6.5A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` NVD ↗ · NTAP-20260724-0002
CVE-2026-3904——— NVD ↗ · NTAP-20260410-0018
CVE-2026-39457——— NVD ↗ · NTAP-20260501-0004
CVE-2026-39461——— NVD ↗ · NTAP-20260527-0007
CVE-2026-39817——— NVD ↗ · NTAP-20260619-0009
CVE-2026-39819——— NVD ↗ · NTAP-20260619-0010
CVE-2026-39820——— NVD ↗ · NTAP-20260612-0005
CVE-2026-39821——— NVD ↗ · NTAP-20260626-0012
CVE-2026-39822——— NVD ↗ · NTAP-20260731-0009
CVE-2026-39823——— NVD ↗ · NTAP-20260619-0008
CVE-2026-39824——— NVD ↗ · NTAP-20260917-0001 · NTAP-20260612-0007
CVE-2026-39825——— NVD ↗ · NTAP-20260619-0011
CVE-2026-39826——— NVD ↗ · NTAP-20260619-0007
CVE-2026-39827——— NVD ↗ · NTAP-20260626-0013
CVE-2026-39828——— NVD ↗ · NTAP-20260617-0019
CVE-2026-39829——— NVD ↗ · NTAP-20260617-0019
CVE-2026-39830——— NVD ↗ · NTAP-20260617-0019
CVE-2026-39831——— NVD ↗ · NTAP-20260617-0019
CVE-2026-39832——— NVD ↗ · NTAP-20260617-0019
CVE-2026-39833——— NVD ↗ · NTAP-20260617-0019
CVE-2026-39834——— NVD ↗ · NTAP-20260617-0019
CVE-2026-39835——— NVD ↗ · NTAP-20260617-0019
CVE-2026-39836——— NVD ↗ · NTAP-20260619-0005
CVE-2026-39865——— NVD ↗ · NTAP-20260422-0002
CVE-2026-39882——— NVD ↗ · NTAP-20260612-0009
CVE-2026-39883——— NVD ↗ · NTAP-20260612-0008
CVE-2026-398922026-04-08CRITICAL9.8cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer NVD ↗ · NTAP-20260917-0001
CVE-2026-399562026-04-13MEDIUM6.1jq is a command-line JSON processor. Prior to version 1.8.2, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() NVD ↗ · NTAP-20260918-0008
CVE-2026-399792026-04-13MEDIUM6.5jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with NVD ↗ · NTAP-20260918-0003
CVE-2026-40021——— NVD ↗ · NTAP-20260522-0002
CVE-2026-40023——— NVD ↗ · NTAP-20260710-0003
CVE-2026-401642026-04-14HIGH7.5jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A NVD ↗ · NTAP-20260918-0002
CVE-2026-40175——— NVD ↗ · NTAP-20260917-0001 · NTAP-20260417-0020
CVE-2026-401792026-04-15MEDIUM6.1Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vu NVD ↗ · NTAP-20260930-0017
CVE-2026-401922026-04-15HIGH7.5Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them NVD ↗ · NTAP-20260917-0001
CVE-2026-40355——— NVD ↗ · NTAP-20260911-0018
CVE-2026-40356——— NVD ↗ · NTAP-20260911-0018
CVE-2026-40372——— NVD ↗ · NTAP-20260429-0003
CVE-2026-40462026-03-30HIGH7.5The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 cha NVD ↗ · NTAP-20260422-0003
CVE-2026-404662026-04-24HIGH8.8Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache Active NVD ↗ · NTAP-20260917-0001
CVE-2026-40622——— NVD ↗ · NTAP-20260626-0001
CVE-2026-40682——— NVD ↗ · NTAP-20260917-0001
CVE-2026-40701——— NVD ↗ · NTAP-20260522-0013
CVE-2026-408642026-05-22MEDIUM5.4JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0 NVD ↗ · NTAP-20260917-0001
CVE-2026-40971——— NVD ↗ · NTAP-20260626-0018
CVE-2026-40972——— NVD ↗ · NTAP-20260605-0013
CVE-2026-40973——— NVD ↗ · NTAP-20260605-0013
CVE-2026-40974——— NVD ↗ · NTAP-20260605-0013
CVE-2026-40975——— NVD ↗ · NTAP-20260605-0013
CVE-2026-40976——— NVD ↗ · NTAP-20260821-0005
CVE-2026-40977——— NVD ↗ · NTAP-20260605-0009
CVE-2026-40993——— NVD ↗ · NTAP-20260731-0011
CVE-2026-410442026-04-24HIGH8.8Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ A NVD ↗ · NTAP-20260917-0001
CVE-2026-41254——— NVD ↗ · NTAP-20260724-0015
CVE-2026-412562026-05-11MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on curr NVD ↗ · NTAP-20260918-0009
CVE-2026-412572026-05-11MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyo NVD ↗ · NTAP-20260918-0004
CVE-2026-41284——— NVD ↗ · NTAP-20260529-0014
CVE-2026-41292——— NVD ↗ · NTAP-20260626-0001
CVE-2026-41293——— NVD ↗ · NTAP-20260529-0014
CVE-2026-414172026-05-06MEDIUM5.3Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `s NVD ↗ · NTAP-20260917-0001 · NTAP-20260717-0004 +1
CVE-2026-415862026-05-07CRITICAL9.8Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Ch NVD ↗ · NTAP-20260917-0002
CVE-2026-41602——— NVD ↗ · NTAP-20260529-0015
CVE-2026-41603——— NVD ↗ · NTAP-20260529-0015
CVE-2026-41604——— NVD ↗ · NTAP-20260529-0015
CVE-2026-41605——— NVD ↗ · NTAP-20260529-0015
CVE-2026-41606——— NVD ↗ · NTAP-20260529-0015
CVE-2026-41607——— NVD ↗ · NTAP-20260529-0015
CVE-2026-41636——— NVD ↗ · NTAP-20260529-0015
CVE-2026-418382026-06-09MEDIUM4.8IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequa NVD ↗ · NTAP-20260924-0007
CVE-2026-41839——— NVD ↗ · NTAP-20260731-0014
CVE-2026-418402026-06-09MEDIUM5.9Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 thro NVD ↗ · NTAP-20260924-0007
CVE-2026-418412026-06-09MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 NVD ↗ · NTAP-20260924-0007
CVE-2026-418422026-06-09HIGH7.5Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 NVD ↗ · NTAP-20260924-0007
CVE-2026-418432026-06-09MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through NVD ↗ · NTAP-20260924-0007
CVE-2026-418442026-06-09MEDIUM4.2A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a li NVD ↗ · NTAP-20260924-0007
CVE-2026-418452026-06-09HIGH7.1Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross- NVD ↗ · NTAP-20260924-0007
CVE-2026-418462026-06-09MEDIUM5.9Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScrip NVD ↗ · NTAP-20260924-0007
CVE-2026-418472026-06-09MEDIUM4.8Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48. NVD ↗ · NTAP-20260924-0010
CVE-2026-418482026-06-09LOW3.7Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or in NVD ↗ · NTAP-20260924-0007
CVE-2026-418492026-06-09HIGH7.5An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially NVD ↗ · NTAP-20260924-0004
CVE-2026-418502026-06-09HIGH7.5Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a NVD ↗ · NTAP-20260924-0007
CVE-2026-418512026-06-09MEDIUM5.3Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of NVD ↗ · NTAP-20260924-0007
CVE-2026-418522026-06-09LOW3.7A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only NVD ↗ · NTAP-20260924-0007
CVE-2026-418532026-06-09MEDIUM5.3Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 throug NVD ↗ · NTAP-20260924-0007
CVE-2026-41854——— NVD ↗ · NTAP-20260717-0017
CVE-2026-41855——— NVD ↗ · NTAP-20260911-0014
CVE-2026-41989——— NVD ↗ · NTAP-20260917-0019
CVE-2026-42027——— NVD ↗ · NTAP-20260917-0001
CVE-2026-42033——— NVD ↗ · NTAP-20260917-0001
CVE-2026-42034——— NVD ↗ · NTAP-20260917-0001
CVE-2026-42035——— NVD ↗ · NTAP-20260917-0001
CVE-2026-42036——— NVD ↗ · NTAP-20260917-0001
CVE-2026-42037——— NVD ↗ · NTAP-20260917-0001
CVE-2026-42038——— NVD ↗ · NTAP-20260917-0001
CVE-2026-42039——— NVD ↗ · NTAP-20260917-0001
CVE-2026-42040——— NVD ↗ · NTAP-20260917-0001
CVE-2026-42041——— NVD ↗ · NTAP-20260917-0001
CVE-2026-42042——— NVD ↗ · NTAP-20260917-0001
CVE-2026-42043——— NVD ↗ · NTAP-20260917-0001
CVE-2026-42044——— NVD ↗ · NTAP-20260917-0001
CVE-2026-421512026-05-04HIGH7.5Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote writ NVD ↗ · NTAP-20260930-0018
CVE-2026-421542026-05-04HIGH7.5Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not va NVD ↗ · NTAP-20260930-0019
CVE-2026-421982026-04-29HIGH7.5pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during S NVD ↗ · NTAP-20260917-0001
CVE-2026-42253——— NVD ↗ · NTAP-20260710-0001
CVE-2026-422642026-05-08HIGH7.4Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPat NVD ↗ · NTAP-20260917-0001
CVE-2026-424022026-05-01HIGH7.5Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trig NVD ↗ · NTAP-20260917-0001
CVE-2026-424032026-05-01HIGH7.5Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (where Policy A NVD ↗ · NTAP-20260917-0001
CVE-2026-424042026-05-01MEDIUM6.5Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the PolicyReference API. When an application expl NVD ↗ · NTAP-20260917-0001
CVE-2026-42440——— NVD ↗ · NTAP-20260917-0001
CVE-2026-4247——— NVD ↗ · NTAP-20260417-0005
CVE-2026-42496——— NVD ↗ · NTAP-20260911-0013
CVE-2026-42498——— NVD ↗ · NTAP-20260522-0010
CVE-2026-42499——— NVD ↗ · NTAP-20260619-0003
CVE-2026-42501——— NVD ↗ · NTAP-20260619-0004
CVE-2026-42502——— NVD ↗ · NTAP-20260626-0012
CVE-2026-42504——— NVD ↗ · NTAP-20260619-0002
CVE-2026-42505——— NVD ↗ · NTAP-20260731-0010
CVE-2026-42506——— NVD ↗ · NTAP-20260626-0012
CVE-2026-42508——— NVD ↗ · NTAP-20260617-0019
CVE-2026-425112026-04-30HIGH8.1The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the le NVD ↗ · NTAP-20260501-0005
CVE-2026-425122026-04-30HIGH8.1As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrec NVD ↗ · NTAP-20260501-0006
CVE-2026-42533——— NVD ↗ · NTAP-20260724-0001
CVE-2026-42534——— NVD ↗ · NTAP-20260626-0001
CVE-2026-42535——— NVD ↗ · NTAP-20260610-0002
CVE-2026-425362026-06-08HIGH7.5Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: fr NVD ↗ · NTAP-20260610-0001
CVE-2026-425772026-05-13HIGH7.5Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP c NVD ↗ · NTAP-20260917-0001
CVE-2026-425782026-05-13HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019
CVE-2026-42579——— NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019
CVE-2026-425802026-05-13MEDIUM6.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 +1
CVE-2026-425812026-05-13MEDIUM5.8Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Le NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 +1
CVE-2026-425832026-05-13HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decom NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 +1
CVE-2026-425842026-05-13HIGH7.3Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 +1
CVE-2026-425852026-05-13MEDIUM6.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encod NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 +1
CVE-2026-42586——— NVD ↗ · NTAP-20260626-0019
CVE-2026-425872026-05-13HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation p NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0019 +1
CVE-2026-42588——— NVD ↗ · NTAP-20260710-0001
CVE-2026-427642026-06-09HIGH7.5Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation d NVD ↗ · NTAP-20260617-0004
CVE-2026-427652026-06-09HIGH7.5Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen NVD ↗ · NTAP-20260617-0005
CVE-2026-427662026-06-09MEDIUM5.9Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointe NVD ↗ · NTAP-20260617-0013
CVE-2026-427672026-06-09MEDIUM5.9Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact NVD ↗ · NTAP-20260617-0012
CVE-2026-427682026-06-09LOW3.7Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME m NVD ↗ · NTAP-20260617-0017
CVE-2026-427692026-06-09MEDIUM5.3Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response r NVD ↗ · NTAP-20260617-0014
CVE-2026-427702026-06-09LOW3.7Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact s NVD ↗ · NTAP-20260617-0018
CVE-2026-427712026-06-09MEDIUM6.2Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, NVD ↗ · NTAP-20260617-0011
CVE-2026-427902026-05-27HIGH8.1Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject Comm NVD ↗ · NTAP-20260605-0010
CVE-2026-42923——— NVD ↗ · NTAP-20260626-0001
CVE-2026-42934——— NVD ↗ · NTAP-20260522-0014
CVE-2026-42944——— NVD ↗ · NTAP-20260626-0001
CVE-2026-42945——— NVD ↗ · NTAP-20260522-0011
CVE-2026-42946——— NVD ↗ · NTAP-20260522-0012
CVE-2026-42959——— NVD ↗ · NTAP-20260626-0001
CVE-2026-42960——— NVD ↗ · NTAP-20260626-0001
CVE-2026-43284——— NVD ↗ · NTAP-20260513-0001
CVE-2026-43499——— NVD ↗ · NTAP-20260710-0018
CVE-2026-43500——— NVD ↗ · NTAP-20260513-0002
CVE-2026-43501——— NVD ↗ · NTAP-20260605-0015
CVE-2026-43503——— NVD ↗ · NTAP-20260710-0019
CVE-2026-43512——— NVD ↗ · NTAP-20260529-0014
CVE-2026-43513——— NVD ↗ · NTAP-20260529-0014
CVE-2026-43514——— NVD ↗ · NTAP-20260529-0014
CVE-2026-43515——— NVD ↗ · NTAP-20260529-0014
CVE-2026-43617——— NVD ↗ · NTAP-20260917-0016
CVE-2026-43618——— NVD ↗ · NTAP-20260917-0017
CVE-2026-43619——— NVD ↗ · NTAP-20260917-0014
CVE-2026-43620——— NVD ↗ · NTAP-20260917-0015
CVE-2026-43868——— NVD ↗ · NTAP-20260529-0015
CVE-2026-438692026-05-05HIGH7.3Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to NVD ↗ · NTAP-20260917-0001 · NTAP-20260529-0015
CVE-2026-43870——— NVD ↗ · NTAP-20260529-0015
CVE-2026-438942026-05-11MEDIUM6.2jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro NVD ↗ · NTAP-20260918-0006
CVE-2026-438952026-05-11MEDIUM4.4jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those path NVD ↗ · NTAP-20260918-0012
CVE-2026-438962026-05-11MEDIUM6.2jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process w NVD ↗ · NTAP-20260918-0007
CVE-2026-439512026-06-08MEDIUM6.5Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: fro NVD ↗ · NTAP-20260610-0001
CVE-2026-4408——— NVD ↗ · NTAP-20260527-0001
CVE-2026-441192026-06-08MEDIUM5.5Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the htt NVD ↗ · NTAP-20260610-0001
CVE-2026-44170——— NVD ↗ · NTAP-20260828-0019
CVE-2026-441852026-06-08HIGH7.3Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: fro NVD ↗ · NTAP-20260610-0001
CVE-2026-441862026-06-08HIGH7.3Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP s NVD ↗ · NTAP-20260610-0001
CVE-2026-44248——— NVD ↗ · NTAP-20260626-0019
CVE-2026-442492026-06-11HIGH8.1Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an NVD ↗ · NTAP-20260917-0005 · NTAP-20260626-0020
CVE-2026-44250——— NVD ↗ · NTAP-20260626-0020
CVE-2026-4426——— NVD ↗ · NTAP-20260417-0007
CVE-2026-4437——— NVD ↗ · NTAP-20260410-0017
CVE-2026-4438——— NVD ↗ · NTAP-20260410-0017
CVE-2026-44390——— NVD ↗ · NTAP-20260626-0001
CVE-2026-44417——— NVD ↗ · NTAP-20260618-0002
CVE-2026-444312026-05-13MEDIUM5.3urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from NVD ↗ · NTAP-20260917-0001 · NTAP-20260724-0004
CVE-2026-44432——— NVD ↗ · NTAP-20260917-0001 · NTAP-20260724-0003
CVE-2026-44578——— NVD ↗ · NTAP-20260529-0013
CVE-2026-44604——— NVD ↗ · NTAP-20260828-0018
CVE-2026-44608——— NVD ↗ · NTAP-20260626-0001
CVE-2026-44618——— NVD ↗ · NTAP-20260618-0003
CVE-2026-446312026-06-08CRITICAL9.8Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 thr NVD ↗ · NTAP-20260610-0001
CVE-2026-447772026-05-11MEDIUM5.5jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules inclu NVD ↗ · NTAP-20260918-0010
CVE-2026-4480——— NVD ↗ · NTAP-20260527-0002
CVE-2026-44890——— NVD ↗ · NTAP-20260626-0020
CVE-2026-44892——— NVD ↗ · NTAP-20260724-0013
CVE-2026-44893——— NVD ↗ · NTAP-20260626-0020
CVE-2026-44894——— NVD ↗ · NTAP-20260724-0013
CVE-2026-449032026-05-26MEDIUM6.1Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabl NVD ↗ · NTAP-20260930-0020
CVE-2026-44930——— NVD ↗ · NTAP-20260618-0001
CVE-2026-4519——— NVD ↗ · NTAP-20260410-0019
CVE-2026-452052026-05-14MEDIUM5.3Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError f NVD ↗ · NTAP-20260917-0001 · NTAP-20260814-0010
CVE-2026-45232——— NVD ↗ · NTAP-20260917-0018
CVE-2026-45250——— NVD ↗ · NTAP-20260527-0009
CVE-2026-45251——— NVD ↗ · NTAP-20260527-0010
CVE-2026-45252——— NVD ↗ · NTAP-20260527-0013
CVE-2026-45253——— NVD ↗ · NTAP-20260527-0008
CVE-2026-45254——— NVD ↗ · NTAP-20260527-0012
CVE-2026-45255——— NVD ↗ · NTAP-20260527-0011
CVE-2026-45256——— NVD ↗ · NTAP-20260626-0004
CVE-2026-45257——— NVD ↗ · NTAP-20260619-0020
CVE-2026-45258——— NVD ↗ · NTAP-20260626-0002
CVE-2026-45259——— NVD ↗ · NTAP-20260626-0005
CVE-2026-45292——— NVD ↗ · NTAP-20260828-0020
CVE-2026-45392026-03-22LOW3.3A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipu NVD ↗ · NTAP-20260917-0001
CVE-2026-45416——— NVD ↗ · NTAP-20260626-0020
CVE-2026-454452026-06-09HIGH7.5Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector NVD ↗ · NTAP-20260617-0007
CVE-2026-454462026-06-09MEDIUM4.8Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an NVD ↗ · NTAP-20260617-0016
CVE-2026-454472026-06-09HIGH8.8Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-af NVD ↗ · NTAP-20260617-0002
CVE-2026-45490——— NVD ↗ · NTAP-20260703-0008
CVE-2026-45491——— NVD ↗ · NTAP-20260703-0009
CVE-2026-45505——— NVD ↗ · NTAP-20260710-0001
CVE-2026-455362026-06-12MEDIUM4.0Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_re NVD ↗ · NTAP-20260917-0001 · NTAP-20260626-0020
CVE-2026-45591——— NVD ↗ · NTAP-20260703-0010
CVE-2026-45673——— NVD ↗ · NTAP-20260626-0020
CVE-2026-45674——— NVD ↗ · NTAP-20260626-0020

Years: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2017 · 2016 · 2015 · 2014 · 2013 · 2012 · 2011 · 2010 · 2009 · 2008 · 2007 · 2006 · 2005 · 2004 · 2003 · 2002 · 1999

← CVE index · Security hub