| CVE-2026-14456 | HIGH | libcrypto3 | 3.6.3-r3 | 3.6.3-r5 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-14456 | HIGH | libssl3 | 3.6.3-r3 | 3.6.3-r5 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-14456 | HIGH | openssl | 3.6.3-r3 | 3.6.3-r5 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-15308 | HIGH | python-3.13-base | 3.13.14-r2 | 3.13.14-r3 | python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations |
| CVE-2026-33818 | HIGH | git-lfs | 3.7.1-r17 | 3.7.1-r19 | encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal |
| CVE-2026-33818 | HIGH | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal |
| CVE-2026-33818 | HIGH | stdlib | 1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal |
| CVE-2026-38754 | HIGH | busybox | 1.37.0-r61 | 1.38.0-r0 | busybox: Busybox: Denial of Service via heap overflow in ifsbreakup() function |
| CVE-2026-39821 | HIGH | git-lfs | 3.7.1-r17 | 3.7.1-r19 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing |
| CVE-2026-39821 | HIGH | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing |
| CVE-2026-39821 | HIGH | stdlib | 1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing |
| CVE-2026-46600 | HIGH | golang.org/x/net | v0.55.0 | 0.56.0 | golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing |
| CVE-2026-46600 | HIGH | stdlib | v1.26.5 | 1.26.6, 1.27.0-rc.3 | golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing |
| CVE-2026-46600 | HIGH | stdlib | 1.26.5 | 1.26.6, 1.27.0-rc.3 | golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing |
| CVE-2026-56852 | HIGH | git-lfs | 3.7.1-r17 | 3.7.1-r18 | golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input |
| CVE-2026-56852 | HIGH | golang.org/x/text | v0.37.0 | 0.39.0 | golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input |
| CVE-2026-56853 | HIGH | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service |
| CVE-2026-56853 | HIGH | stdlib | 1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service |
| CVE-2026-56854 | HIGH | golang.org/x/crypto | v0.52.0 | 0.55.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions |
| CVE-2026-56858 | HIGH | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | html/template: golang: Go html/template: Cross-Site Scripting via pathological input |
| CVE-2026-56858 | HIGH | stdlib | 1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | html/template: golang: Go html/template: Cross-Site Scripting via pathological input |
| CVE-2026-56859 | HIGH | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue |
| CVE-2026-56859 | HIGH | stdlib | 1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue |
| CVE-2026-56860 | HIGH | git-lfs | 3.7.1-r17 | 3.7.1-r19 | net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution |
| CVE-2026-56860 | HIGH | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution |
| CVE-2026-56860 | HIGH | stdlib | 1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution |
| CVE-2026-56862 | HIGH | git-lfs | 3.7.1-r17 | 3.7.1-r19 | crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages |
| CVE-2026-56862 | HIGH | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages |
| CVE-2026-56862 | HIGH | stdlib | 1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages |
| CVE-2026-69246 | HIGH | guzzlehttp/guzzle | 7.14.2 | 7.15.2, 8.0.1 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Gu ... |
| CVE-2026-71488 | HIGH | league/commonmark | 2.8.3 | 2.9.0 | league/commonmark is a PHP library for parsing and rendering CommonMar ... |
| GHSA-8rr7-cvq3-gmfh | HIGH | league/commonmark | 2.8.3 | 2.10.0 | league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension |
| GHSA-f8fg-pg57-v4j8 | HIGH | league/commonmark | 2.8.3 | 2.9.1 | league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed |
| GHSA-g2gp-3wwq-f4ph | HIGH | league/commonmark | 2.8.3 | 2.9.0 | league/commonmark: Denial of service via adjacent inline attribute blocks |
| GHSA-j8pm-gj4c-rq4x | HIGH | league/commonmark | 2.8.3 | 2.9.1 | league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters |
| GHSA-jfm3-95jq-q3rf | HIGH | league/commonmark | 2.8.3 | 2.9.0 | league/commonmark: Denial of service via duplicate footnote definitions |
| GHSA-jjv6-8j6v-6j52 | HIGH | league/commonmark | 2.8.3 | 2.9.1 | league/commonmark: Denial of service in the SmartPunct and Attributes extensions |
| GHSA-mh25-x5hq-wrqp | HIGH | league/commonmark | 2.8.3 | 2.9.0 | league/commonmark: Denial of service via colliding heading slugs |
| CVE-2025-15366 | MEDIUM | python-3.13-base | 3.13.14-r2 | 3.13.15-r0 | cpython: IMAP command injection in user-controlled commands |
| CVE-2026-13346 | MEDIUM | pip | 26.1.2 | 26.2.0 | pip: pip: Arbitrary file installation via malicious package indexes |
| CVE-2026-15806 | MEDIUM | python-3.13-base | 3.13.14-r2 | 3.13.15-r5 | python: Python: Information disclosure due to incorrect URL scheme matching |
| CVE-2026-17084 | MEDIUM | python-3.13-base | 3.13.14-r2 | 3.13.15-r6 | python: Python stringprep module: Incorrect domain name processing breaks IDNA interoperability |
| CVE-2026-38752 | MEDIUM | busybox | 1.37.0-r61 | 1.38.0-r1 | busybox: BusyBox: Denial of Service via crafted AWK script |
| CVE-2026-38753 | MEDIUM | busybox | 1.37.0-r61 | 1.38.0-r0 | busybox: Busybox: Denial of Service via crafted AWK script in awk_sub() function |
| CVE-2026-38755 | MEDIUM | busybox | 1.37.0-r61 | 1.38.0-r0 | busybox: Busybox: Denial of Service via heap overflow in evalcommand() function |
| CVE-2026-56855 | MEDIUM | golang.org/x/crypto | v0.52.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages |
| CVE-2026-58055 | MEDIUM | libnghttp2-14 | 1.69.0-r0 | 1.70.0-r0 | nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests |
| CVE-2026-67353 | MEDIUM | guzzlehttp/guzzle | 7.14.2 | 7.15.1 | guzzlehttp/guzzle: guzzlehttp/guzzle: Denial of Service via unbounded cookie storage |
| CVE-2026-67354 | MEDIUM | guzzlehttp/guzzle | 7.14.2 | 7.15.1 | guzzlehttp/guzzle: guzzlehttp/guzzle: URI Fragment Disclosure in Referer Header |
| CVE-2026-67355 | MEDIUM | guzzlehttp/guzzle | 7.14.2 | 7.15.1 | guzzlehttp/guzzle: guzzlehttp/guzzle: Information disclosure from host-only cookie scope issue |
| CVE-2026-69245 | MEDIUM | guzzlehttp/guzzle | 7.14.2 | 7.15.2, 8.0.1 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Se ... |
| CVE-2026-71478 | MEDIUM | league/commonmark | 2.8.3 | 2.9.0 | league/commonmark is a PHP library for parsing and rendering CommonMar ... |
| CVE-2026-78662 | MEDIUM | golang.org/x/crypto | v0.52.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding |
| CVE-2026-81887 | MEDIUM | livewire/livewire | v3.8.0 | 3.8.3, 4.3.4 | Livewire DOM-based cross-site scripting during client-side state handling |
| CVE-2026-82209 | MEDIUM | libcurl-openssl4 | 8.21.0-r1 | 8.22.0-r2 | When libpsl support is enabled, libcurl fails to enforce the Public Su ... |
| CVE-2026-85091 | MEDIUM | zlib | 1.3.2-r3 | 1.3.3-r0 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... |
| GHSA-mj63-m3rc-8ppr | MEDIUM | league/commonmark | 2.8.3 | 2.9.0 | league/commonmark: Denial of service via deeply nested XML output |
| CVE-2026-54876 | LOW | libcrypto3 | 3.6.3-r3 | 3.6.3-r4 | openssl: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking |
| CVE-2026-54876 | LOW | libssl3 | 3.6.3-r3 | 3.6.3-r4 | openssl: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking |
| CVE-2026-54876 | LOW | openssl | 3.6.3-r3 | 3.6.3-r4 | openssl: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking |
| CVE-2026-6879 | LOW | python-3.13-base | 3.13.14-r2 | 3.13.15-r0 | python: Python: Performance degradation in XML processing due to quadratic time complexity |
| GO-2026-5932 | UNKNOWN | golang.org/x/crypto | v0.52.0 | — sin corrección | The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues |