| CVE-2026-54133 | CRITICAL | mtdowling/jmespath.php | 2.8.0 | 2.9.1 | CompilerRuntime code injection via unescaped function names |
| CVE-2026-11940 | HIGH | python-3.13-base | 3.13.14-r0 | 3.13.14-r2 | python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory |
| CVE-2026-14456 | HIGH | libcrypto3 | 3.6.3-r3 | 3.6.3-r5 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-14456 | HIGH | libssl3 | 3.6.3-r3 | 3.6.3-r5 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-14456 | HIGH | openssl | 3.6.3-r3 | 3.6.3-r5 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-15308 | HIGH | python-3.13-base | 3.13.14-r0 | 3.13.14-r3 | python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations |
| CVE-2026-38754 | HIGH | busybox | 1.37.0-r61 | 1.38.0-r0 | busybox: Busybox: Denial of Service via heap overflow in ifsbreakup() function |
| CVE-2026-45071 | HIGH | symfony/dom-crawler | v6.4.23 | 6.4.40, 7.4.12, 8.0.12, 3.0.0, 4.0.0, 6.2.0, 5.1.0, 5.4.52, 6.3.0, 7.1.0, 7.2.0, 7.3.0, 5.0.0, 5.3.0, 5.4.0, 7.4.0, 5.2.0, 6.1.0, 6.4.0 | Symfony is a PHP framework for web and console applications and a set ... |
| CVE-2026-69246 | HIGH | guzzlehttp/guzzle | 7.9.3 | 7.15.2, 8.0.1 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Gu ... |
| CVE-2025-15366 | MEDIUM | python-3.13-base | 3.13.14-r0 | 3.13.15-r0 | cpython: IMAP command injection in user-controlled commands |
| CVE-2026-0864 | MEDIUM | python-3.13-base | 3.13.14-r0 | 3.13.14-r2 | python: cpython: Python configparser: Configuration injection via crafted multi-line input |
| CVE-2026-11972 | MEDIUM | python-3.13-base | 3.13.14-r0 | 3.13.14-r2 | python: Python tarfile module: Denial of Service via improper EOF handling in streaming mode |
| CVE-2026-13346 | MEDIUM | pip | 26.1.2 | 26.2.0 | pip: pip: Arbitrary file installation via malicious package indexes |
| CVE-2026-15806 | MEDIUM | python-3.13-base | 3.13.14-r0 | 3.13.15-r5 | python: Python: Information disclosure due to incorrect URL scheme matching |
| CVE-2026-17084 | MEDIUM | python-3.13-base | 3.13.14-r0 | 3.13.15-r6 | python: Python stringprep module: Incorrect domain name processing breaks IDNA interoperability |
| CVE-2026-38752 | MEDIUM | busybox | 1.37.0-r61 | 1.38.0-r1 | busybox: BusyBox: Denial of Service via crafted AWK script |
| CVE-2026-38753 | MEDIUM | busybox | 1.37.0-r61 | 1.38.0-r0 | busybox: Busybox: Denial of Service via crafted AWK script in awk_sub() function |
| CVE-2026-38755 | MEDIUM | busybox | 1.37.0-r61 | 1.38.0-r0 | busybox: Busybox: Denial of Service via heap overflow in evalcommand() function |
| CVE-2026-4360 | MEDIUM | python-3.13-base | 3.13.14-r0 | 3.13.14-r2 | python: Python Tarfile: Unexpected file ownership when extracting hardlinks |
| CVE-2026-48998 | MEDIUM | guzzlehttp/psr7 | 2.7.1 | 2.10.2 | guzzlehttp/psr7: guzzlehttp/psr7: Information disclosure via improper Host header validation |
| CVE-2026-49214 | MEDIUM | guzzlehttp/psr7 | 2.7.1 | 2.10.2 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ... |
| CVE-2026-55568 | MEDIUM | guzzlehttp/guzzle | 7.9.3 | 7.12.1 | Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain c ... |
| CVE-2026-55599 | MEDIUM | phpseclib/phpseclib | 2.0.54 | 1.0.30, 2.0.55, 3.0.54 | phpseclib is a PHP secure communications library. From 0.1.1 until 1.0 ... |
| CVE-2026-55766 | MEDIUM | guzzlehttp/psr7 | 2.7.1 | 2.12.1 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ... |
| CVE-2026-55767 | MEDIUM | guzzlehttp/guzzle | 7.9.3 | 7.12.1 | Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar in ... |
| CVE-2026-58055 | MEDIUM | libnghttp2-14 | 1.69.0-r0 | 1.70.0-r0 | nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests |
| CVE-2026-59882 | MEDIUM | guzzlehttp/psr7 | 2.7.1 | 2.12.3 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ... |
| CVE-2026-59883 | MEDIUM | guzzlehttp/guzzle | 7.9.3 | 7.12.3 | guzzle/guzzle: Guzzle: Cross-host cookie disclosure and injection due to improper domain matching in CookieJar. |
| CVE-2026-67339 | MEDIUM | guzzlehttp/guzzle | 7.9.3 | 7.14.2 | guzzlehttp/guzzle: guzzlehttp/guzzle: Proxy-Authorization header disclosure via improper isolation |
| CVE-2026-67353 | MEDIUM | guzzlehttp/guzzle | 7.9.3 | 7.15.1 | guzzlehttp/guzzle: guzzlehttp/guzzle: Denial of Service via unbounded cookie storage |
| CVE-2026-67354 | MEDIUM | guzzlehttp/guzzle | 7.9.3 | 7.15.1 | guzzlehttp/guzzle: guzzlehttp/guzzle: URI Fragment Disclosure in Referer Header |
| CVE-2026-67355 | MEDIUM | guzzlehttp/guzzle | 7.9.3 | 7.15.1 | guzzlehttp/guzzle: guzzlehttp/guzzle: Information disclosure from host-only cookie scope issue |
| CVE-2026-6791 | MEDIUM | glibc | 2.43-r9 | 2.43-r10 | glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion |
| CVE-2026-6791 | MEDIUM | glibc-locale-posix | 2.43-r9 | 2.43-r10 | glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion |
| CVE-2026-6791 | MEDIUM | ld-linux | 2.43-r9 | 2.43-r10 | glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion |
| CVE-2026-6791 | MEDIUM | libcrypt1 | 2.43-r9 | 2.43-r10 | glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion |
| CVE-2026-69245 | MEDIUM | guzzlehttp/guzzle | 7.9.3 | 7.15.2, 8.0.1 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Se ... |
| CVE-2026-82209 | MEDIUM | libcurl-openssl4 | 8.21.0-r1 | 8.22.0-r2 | When libpsl support is enabled, libcurl fails to enforce the Public Su ... |
| CVE-2026-85091 | MEDIUM | zlib | 1.3.2-r3 | 1.3.3-r0 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... |
| CVE-2026-54876 | LOW | libcrypto3 | 3.6.3-r3 | 3.6.3-r4 | openssl: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking |
| CVE-2026-54876 | LOW | libssl3 | 3.6.3-r3 | 3.6.3-r4 | openssl: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking |
| CVE-2026-54876 | LOW | openssl | 3.6.3-r3 | 3.6.3-r4 | openssl: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking |
| CVE-2026-6879 | LOW | python-3.13-base | 3.13.14-r0 | 3.13.15-r0 | python: Python: Performance degradation in XML processing due to quadratic time complexity |
| GHSA-gq4g-fpc9-vjfq | LOW | web-auth/webauthn-lib | 4.9.2 | 5.3.5 | Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection |