Search CVE reports


Toggle filters

11 – 20 of 331 results


CVE-2026-42766

Low priority

Some fixes available 9 of 17

Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference leads to an application crash and a Denial of...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Fixed
Show less packages

CVE-2026-42765

Low priority
Vulnerable

Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Not affected Not affected Not affected Not affected Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
openssl Not affected Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages

CVE-2026-42764

Medium priority

Some fixes available 2 of 4

Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer dereference typically causes...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Needs evaluation Not affected Not affected Not affected Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages

CVE-2026-35188

Medium priority
Vulnerable

Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path. Impact summary:...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Not affected Not affected Not affected Not affected Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
openssl Not affected Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages

CVE-2026-34183

Medium priority

Some fixes available 2 of 5

Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Needs evaluation Not affected Not affected Not affected Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages

CVE-2026-34182

Medium priority

Some fixes available 4 of 8

Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises. Impact...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Needs evaluation Needs evaluation Not affected Not affected Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages

CVE-2026-34181

Low priority

Some fixes available 2 of 5

Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Needs evaluation Not affected Not affected Not affected Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages

CVE-2026-34180

Low priority

Some fixes available 9 of 17

Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms. Impact summary: The heap...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Fixed
Show less packages

CVE-2026-8721

Medium priority
Needs evaluation

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to SvPV_nolen. The Perl length is...

1 affected package

libcrypt-openssl-pkcs12-perl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-openssl-pkcs12-perl Needs evaluation Needs evaluation Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-8507

Medium priority
Needs evaluation

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap...

1 affected package

libcrypt-openssl-pkcs12-perl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libcrypt-openssl-pkcs12-perl Needs evaluation Needs evaluation Not in release Needs evaluation Needs evaluation
Show less packages