Search CVE reports


Toggle filters

11 – 20 of 121 results


CVE-2026-42766

Low priority

Some fixes available 9 of 17

Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference leads to an application crash and a Denial of...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Fixed
Show less packages

CVE-2026-42765

Low priority
Vulnerable

Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Not affected Not affected Not affected Not affected Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
openssl Not affected Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages

CVE-2026-42764

Medium priority

Some fixes available 2 of 4

Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer dereference typically causes...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Needs evaluation Not affected Not affected Not affected Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages

CVE-2026-35188

Medium priority
Vulnerable

Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path. Impact summary:...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Not affected Not affected Not affected Not affected Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
openssl Not affected Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages

CVE-2026-34183

Medium priority

Some fixes available 2 of 5

Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Needs evaluation Not affected Not affected Not affected Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages

CVE-2026-34182

Medium priority

Some fixes available 4 of 8

Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises. Impact...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Needs evaluation Needs evaluation Not affected Not affected Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages

CVE-2026-34181

Low priority

Some fixes available 2 of 5

Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Needs evaluation Not affected Not affected Not affected Not affected
nodejs Not affected Not affected Vulnerable Not affected Not affected
openssl Fixed Not affected Not affected Not affected Not affected
openssl-fips Not in release Not affected Not affected
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages

CVE-2026-34180

Low priority

Some fixes available 9 of 17

Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms. Impact summary: The heap...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
nodejs Not affected Not affected Vulnerable Not affected Needs evaluation
openssl Fixed Fixed Fixed Fixed Fixed
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Fixed
Show less packages

CVE-2026-31790

Medium priority

Some fixes available 4 of 7

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Vulnerable Vulnerable Not affected Not affected Not affected
nodejs Not affected Not affected Not affected Not affected Not affected
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages

CVE-2026-31789

Low priority

Some fixes available 4 of 7

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker...

5 affected packages

edk2, nodejs, openssl, openssl-fips, openssl1.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
edk2 Vulnerable Vulnerable Not affected Not affected Not affected
nodejs Not affected Not affected Not affected Not affected Not affected
openssl Fixed Fixed Fixed Not affected Not affected
openssl-fips Not in release Not in release Not in release
openssl1.0 Not in release Not in release Not in release Not affected
Show less packages