Search CVE reports


Toggle filters

41 – 50 of 49208 results

Status is adjusted based on your filters.


CVE-2026-102560

Medium priority
Needs evaluation

A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-102559

Medium priority
Needs evaluation

A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-102558

Medium priority
Needs evaluation

A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-102555

Medium priority
Needs evaluation

A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-102635

Medium priority
Needs evaluation

ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number...

1 affected package

imagemagick

Package 24.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-102633

Medium priority
Needs evaluation

libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with...

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 24.04 LTS
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 Not in release
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Not in release
cadaver Needs evaluation
gdcm Not affected
ayttm Not in release
cableswig Not in release
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk Not in release
smart Not in release
firefox Not affected
thunderbird Not affected
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-102557

Medium priority
Needs evaluation

A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-102556

Medium priority
Needs evaluation

A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting...

2 affected packages

libsoup2.4, libsoup3

Package 24.04 LTS
libsoup2.4 Needs evaluation
libsoup3 Needs evaluation
Show less packages

CVE-2026-54873

Low priority
Not affected

Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 24.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
edk2-hwe Not in release
Show less packages

CVE-2026-42772

Low priority
Not affected

Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the...

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 24.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
edk2-hwe Not in release
Show less packages