Search CVE reports


Toggle filters

1211 – 1220 of 35647 results

Status is adjusted based on your filters.


CVE-2026-42039

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js...

1 affected package

node-axios

Package 24.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-42038

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still...

1 affected package

node-axios

Package 24.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-42037

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the Content-Type header of each...

1 affected package

node-axios

Package 24.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-42036

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured...

1 affected package

node-axios

Package 24.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-42035

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP...

1 affected package

node-axios

Package 24.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-42034

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path)....

1 affected package

node-axios

Package 24.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-42033

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can...

1 affected package

node-axios

Package 24.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-41898

Medium priority
Needs evaluation

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and...

1 affected package

rust-openssl

Package 24.04 LTS
rust-openssl Needs evaluation
Show less packages

CVE-2026-41681

Medium priority
Vulnerable

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than...

1 affected package

rust-openssl

Package 24.04 LTS
rust-openssl Vulnerable
Show less packages

CVE-2026-41680

Medium priority
Not affected

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (\x09\x0b\n)—an...

1 affected package

node-marked

Package 24.04 LTS
node-marked Not affected
Show less packages