Search CVE reports


Toggle filters

1 – 10 of 1670 results


CVE-2026-84445

Medium priority

Not in release

gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the...

1 affected package

golang-github-googlecloudplatform-grpc-gcp-go

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-googlecloudplatform-grpc-gcp-go Not in release Not in release Not in release
Show less packages

CVE-2026-83530

Medium priority
Needs evaluation

A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit...

1 affected package

golang-github-google-cel-go

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-google-cel-go Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-87819

Medium priority
Needs evaluation

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field...

1 affected package

python-git

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-git Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-87818

Medium priority
Needs evaluation

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to...

1 affected package

python-git

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-git Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-87817

Medium priority
Needs evaluation

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by...

1 affected package

python-git

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-git Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-19201

Medium priority
Needs evaluation

An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denial of service (DoS). The (*WinEvents).readELAMAggregation...

1 affected package

golang-github-google-go-attestation

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-google-go-attestation Needs evaluation Not in release Not in release
Show less packages

CVE-2026-37236

Medium priority
Needs evaluation

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type...

1 affected package

golang-github-grpc-ecosystem-grpc-gateway

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-grpc-ecosystem-grpc-gateway Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-79921

Medium priority
Needs evaluation

amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This...

1 affected package

golang-github-rabbitmq-amqp091-go

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-rabbitmq-amqp091-go Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2026-77354

Medium priority
Needs evaluation

kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.sliceMapToSlice in openapi3filter/req_resp_decoder.go converts attacker-controlled sparse indexes from a deepObject query parameter...

1 affected package

golang-github-getkin-kin-openapi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-getkin-kin-openapi Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-76905

Medium priority
Needs evaluation

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is...

1 affected package

golang-github-getkin-kin-openapi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-getkin-kin-openapi Needs evaluation Needs evaluation Needs evaluation
Show less packages