Search CVE reports


Toggle filters

171 – 180 of 42176 results

Status is adjusted based on your filters.


CVE-2026-54387

Medium priority
Needs evaluation

Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding both verbatim to the backend while using Content-Length to determine how many...

1 affected package

tinyproxy

Package 22.04 LTS
tinyproxy Needs evaluation
Show less packages

CVE-2026-48823

Medium priority

Not in release

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the tag filtering functionality of Shaarli. An authenticated user can inject arbitrary JavaScript...

1 affected package

shaarli

Package 22.04 LTS
shaarli Not in release
Show less packages

CVE-2026-48822

Medium priority

Not in release

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the Markdown-to-HTML conversion process used in the Bookmark Description field. An authenticated...

1 affected package

shaarli

Package 22.04 LTS
shaarli Not in release
Show less packages

CVE-2026-48817

Medium priority
Needs evaluation

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without...

1 affected package

starlette

Package 22.04 LTS
starlette Needs evaluation
Show less packages

CVE-2026-48818

Medium priority
Needs evaluation

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound...

1 affected package

starlette

Package 22.04 LTS
starlette Needs evaluation
Show less packages

CVE-2026-9697

Medium priority

Not in release

Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store,...

1 affected package

node-undici

Package 22.04 LTS
node-undici Not in release
Show less packages

CVE-2026-9679

Medium priority

Not in release

Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 ยง5.4 does not specify any...

1 affected package

node-undici

Package 22.04 LTS
node-undici Not in release
Show less packages

CVE-2026-9678

Medium priority

Not in release

Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or...

1 affected package

node-undici

Package 22.04 LTS
node-undici Not in release
Show less packages

CVE-2026-6734

Medium priority

Not in release

Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected...

1 affected package

node-undici

Package 22.04 LTS
node-undici Not in release
Show less packages

CVE-2026-6733

Medium priority

Not in release

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a...

1 affected package

node-undici

Package 22.04 LTS
node-undici Not in release
Show less packages