Search CVE reports


Toggle filters

31 – 40 of 41090 results

Status is adjusted based on your filters.


CVE-2026-107353

Medium priority
Needs evaluation

traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path...

1 affected package

node-traverse

Package 26.04 LTS
node-traverse Needs evaluation
Show less packages

CVE-2026-107315

Medium priority
Needs evaluation

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 through 42.7.13 pads a value that is shorter than its declared length with bytes left in its send buffer instead of zeros, and the server stores those bytes as part of the value....

1 affected package

libpgjava

Package 26.04 LTS
libpgjava Needs evaluation
Show less packages

CVE-2026-107314

Medium priority
Needs evaluation

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for...

1 affected package

libpgjava

Package 26.04 LTS
libpgjava Needs evaluation
Show less packages

CVE-2026-107313

Medium priority
Not affected

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 and 42.7.5 can send the previous contents of the GSS send buffer in place of the first part of a value on a connection with GSS encryption (gssEncMode=prefer or require), and the...

1 affected package

libpgjava

Package 26.04 LTS
libpgjava Not affected
Show less packages

CVE-2026-107285

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, a proxied ws request is carried through CONNECT,...

1 affected package

async-http-client

Package 26.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107284

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, WebSocketHandler.upgrade aborts a handshake...

1 affected package

async-http-client

Package 26.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107283

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with...

1 affected package

async-http-client

Package 26.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107282

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, cross-host request replay updates the current request but leaves...

1 affected package

async-http-client

Package 26.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107281

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, the HTTP/1.1 connection-pool key excludes the authenticated...

1 affected package

async-http-client

Package 26.04 LTS
async-http-client Needs evaluation
Show less packages

CVE-2026-107280

Medium priority
Needs evaluation

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.13 and 2.16.1, ThreadSafeCookieStore validates Domain attributes with domain...

1 affected package

async-http-client

Package 26.04 LTS
async-http-client Needs evaluation
Show less packages