Search CVE reports


Toggle filters

91 – 100 of 59858 results

Status is adjusted based on your filters.


CVE-2026-73637

Medium priority
Needs evaluation

Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent...

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-73636

Medium priority
Needs evaluation

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via...

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-68496

Medium priority
Needs evaluation

The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this...

1 affected package

jackson-dataformat-smile

Package 16.04 LTS
jackson-dataformat-smile Needs evaluation
Show less packages

CVE-2026-68495

Medium priority
Needs evaluation

The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this...

1 affected package

jackson-dataformat-cbor

Package 16.04 LTS
jackson-dataformat-cbor Needs evaluation
Show less packages

CVE-2026-63718

Medium priority
Needs evaluation

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects...

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-63686

Medium priority
Needs evaluation

A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose...

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-63292

Medium priority
Needs evaluation

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP...

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-63045

Medium priority
Needs evaluation

Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to...

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-61813

Medium priority
Needs evaluation

[GHSA-2vqc-36qp-ccmw: Weak libcurl TLS hostname verification setting when fetching over HTTPS]

2 affected packages

modsecurity, modsecurity-apache

Package 16.04 LTS
modsecurity —
modsecurity-apache Needs evaluation
Show less packages

CVE-2026-61812

Medium priority
Needs evaluation

[GHSA-cxqf-vgrr-xxrv: HTML decoder missing entities, leading to evasion]

2 affected packages

modsecurity, modsecurity-apache

Package 16.04 LTS
modsecurity —
modsecurity-apache Needs evaluation
Show less packages