Search CVE reports


Toggle filters

151 – 160 of 32959 results

Status is adjusted based on your filters.


CVE-2026-67590

Medium priority
Needs evaluation

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version...

1 affected package

qpid-proton

Package 26.04 LTS
qpid-proton Needs evaluation
Show less packages

CVE-2026-71192

Medium priority
Needs evaluation

In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed...

1 affected package

swift

Package 26.04 LTS
swift Needs evaluation
Show less packages

CVE-2026-71191

Medium priority
Needs evaluation

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned...

1 affected package

swift

Package 26.04 LTS
swift Needs evaluation
Show less packages

CVE-2026-71190

Medium priority
Needs evaluation

In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows an unauthenticated remote attacker...

1 affected package

swift

Package 26.04 LTS
swift Needs evaluation
Show less packages

CVE-2026-67589

Medium priority
Needs evaluation

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade...

1 affected package

qpid-proton

Package 26.04 LTS
qpid-proton Needs evaluation
Show less packages

CVE-2026-67588

Medium priority
Needs evaluation

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to...

1 affected package

qpid-proton

Package 26.04 LTS
qpid-proton Needs evaluation
Show less packages

CVE-2026-55707

Medium priority
Needs evaluation

In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating...

1 affected package

neutron

Package 26.04 LTS
neutron Needs evaluation
Show less packages

CVE-2026-46334

Medium priority

Not in release

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type:...

1 affected package

opensips

Package 26.04 LTS
opensips Not in release
Show less packages

CVE-2026-45809

Medium priority

Not in release

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the watcherinfo generation functionality. An attacker can create an...

1 affected package

opensips

Package 26.04 LTS
opensips Not in release
Show less packages

CVE-2026-45705

Medium priority

Not in release

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when...

1 affected package

opensips

Package 26.04 LTS
opensips Not in release
Show less packages