Search CVE reports


Toggle filters

41 – 50 of 42506 results

Status is adjusted based on your filters.


CVE-2026-33940

Medium priority
Needs evaluation

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context can bypass all conditional guards in `resolvePartial()` and cause...

1 affected package

node-handlebars

Package 18.04 LTS
node-handlebars Needs evaluation
Show less packages

CVE-2026-33939

Medium priority
Needs evaluation

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. `{{*n}}`), the...

1 affected package

node-handlebars

Package 18.04 LTS
node-handlebars Needs evaluation
Show less packages

CVE-2026-33938

Medium priority
Needs evaluation

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template data context and is reachable and mutable from within...

1 affected package

node-handlebars

Package 18.04 LTS
node-handlebars Needs evaluation
Show less packages

CVE-2026-33937

Medium priority
Needs evaluation

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a...

1 affected package

node-handlebars

Package 18.04 LTS
node-handlebars Needs evaluation
Show less packages

CVE-2026-33936

Medium priority
Needs evaluation

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH...

1 affected package

python-ecdsa

Package 18.04 LTS
python-ecdsa Needs evaluation
Show less packages

CVE-2026-33916

Medium priority
Needs evaluation

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials`...

1 affected package

node-handlebars

Package 18.04 LTS
node-handlebars Needs evaluation
Show less packages

CVE-2026-33898

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui`...

2 affected packages

incus, lxd

Package 18.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-33897

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus allows for pongo2 templates within instances...

2 affected packages

incus, lxd

Package 18.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-33871

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of...

1 affected package

netty

Package 18.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-33870

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling...

1 affected package

netty

Package 18.04 LTS
netty Needs evaluation
Show less packages