Skip to content
All tracked CVEs

Updated 09:01

241 fixed in the last 7 days

Severity
CVEStatusSeveritySummaryDistributionFixed
FixedHighValkey clusterbus ping extension parsing out-of-bounds read causes crashsecure-packages-rollingSep 17, 2026
FixedHighValkey Lua null-byte error handling bug allows response stream injection and cross-user data tamperingsecure-packages-rollingSep 17, 2026
FixedCriticalRedis Lua GC use-after-free allows authenticated RCE in versions <=8.2.1; fixed 8.2.2secure-packages-rollingSep 17, 2026
FixedMediumPYSEC-2026-1999: urllib3 PoolManager retries ignored; cannot disable redirects globally, posing SSRF risksecure-packages-25.11Sep 16, 2026
FixedHighPYSEC-2026-1998: urllib3 ≤2.5.0 unbounded decompression chain enables resource exhaustion via chained Content-Encodingsecure-packages-25.11Sep 16, 2026
FixedHighPYSEC-2026-1996: urllib3 ≤2.6.2 decompresses redirect bodies during streaming, enabling decompression bombs and resource exhaustionsecure-packages-25.11Sep 16, 2026
FixedMediumPYSEC-2026-1995: urllib3 fails to strip Proxy-Authorization on cross-origin redirects without ProxyManager, potential credential leaksecure-packages-25.11Sep 16, 2026
FixedHighPYSEC-2026-1994: Resource exhaustion via over-decompression in urllib3 streaming compressed responses (<=2.5.0)secure-packages-25.11Sep 16, 2026
FixedMediumPYSEC-2026-141: urllib3 1.23 to <2.7.0 leaks sensitive headers on cross-origin redirects via ProxyManagersecure-packages-25.11Sep 16, 2026
FixedHighGHSA-qccp-gfcp-xxvc: urllib3 pre-2.7.0 ProxyManager.connection_from_url urlopen forwards sensitive headers on cross-origin redirectssecure-packages-25.11Sep 16, 2026
FixedMediumGHSA-pq67-6m6q-mj2v: urllib3 PoolManager retries ignored; redirects not disabled, causing potential SSRF exposuresecure-packages-25.11Sep 16, 2026
FixedHighGHSA-gm62-xv2j-4w53: urllib3 ≤2.5.0 unbounded content-encoding chain allows CPU and memory exhaustion DoSsecure-packages-25.11Sep 16, 2026
FixedHighGHSA-38jv-5279-wg99: urllib3 decompresses redirect bodies with preload_content=False, ignoring read limits; decompression bomb risksecure-packages-25.11Sep 16, 2026
FixedMediumGHSA-34jh-p97f-mpxf: Proxy-Authorization header may leak on cross-origin redirects when not using urllib3 proxy supportsecure-packages-25.11Sep 16, 2026
FixedHighGHSA-2xpw-w6gg-jr37: urllib3 <=2.5.0 streaming decompression over-decodes compressed responses, causing excessive CPU/memory usagesecure-packages-25.11Sep 16, 2026
FixedHighPYSEC-2026-3457: pyasn1 <0.6.4 REAL float conversion CPU/memory exhaustion via huge exponents in encoded datasecure-packages-25.11Sep 16, 2026
FixedHighPYSEC-2026-3456: pyasn1 <0.6.4 BER/CER/DER OID quadratic-time decode/encode enables DoS with many arcssecure-packages-25.11Sep 16, 2026
FixedHighPYSEC-2026-3455: pyasn1 <0.6.4 BER/CER/DER decoder unbounded long-form tag parsing causes DoS and ValueErrorsecure-packages-25.11Sep 16, 2026
FixedHighPYSEC-2026-2263: Decoding ASN.1 deeply nested indefinite-length SEQUENCE/SET triggers DoS in pyasn1 <0.6.3secure-packages-25.11Sep 16, 2026
FixedHighGHSA-m4p7-r5rc-7g4j: pyasn1 BER/CER/DER decoder unbounded tag IDs cause quadratic CPU and unhandled ValueErrorsecure-packages-25.11Sep 16, 2026
FixedHighGHSA-jr27-m4p2-rc6r: pyasn1 BER decoder DoS via uncontrolled recursion on deeply nested indefinite SEQUENCE/SET causing RecursionError/OOMsecure-packages-25.11Sep 16, 2026
FixedHighGHSA-hm4w-wwcw-mr6r: pyasn1 Real float conversion DoS from untrusted ASN.1 REAL with huge exponentsecure-packages-25.11Sep 16, 2026
FixedHighGHSA-8ppf-4f7h-5ppj: pyasn1 OID/Relative-OID BER/CER/DER encode/decode quadratic by arcs, causing DoSsecure-packages-25.11Sep 16, 2026
FixedHighsecure-packages-25.11Sep 16, 2026
FixedHighRISC-V: Uninitialized cregs overwrite pt_regs after copyin failure, corrupting registers/leaking stacksecure-packages-25.11Sep 15, 2026
FixedHighebtables lacked two-stage removal, exposing partially initialized table via racy ops assignmentsecure-packages-25.11Sep 15, 2026
FixedHighCore ebtables init race: sockopts exposed globally before initialization completessecure-packages-25.11Sep 15, 2026
FixedHighLinux kernel netfs_read_folio() fails to wait on writeback, misinterpreting dirty flag and folio->privatesecure-packages-25.11Sep 15, 2026
FixedCriticalEVP_Cipher() skips AEAD tag verification on empty ciphertext for ChaCha20-Poly1305 and AES-OCBsecure-packages-26.05Sep 15, 2026
FixedHighOpenSSL CMP fails to type-check protectionAlg; invalid cast triggers NULL deref DoSsecure-packages-26.05Sep 15, 2026
FixedHighOpenSSL QUIC retains ACK-only packet metadata, causing unbounded memory growth and DoS risk.secure-packages-26.05Sep 15, 2026
FixedMediumOpenSSL CMP extraCerts cached indefinitely causing unbounded memory growth/DoS with reused OSSL_CMP_CTXsecure-packages-26.05Sep 15, 2026
FixedCriticalOpenSSL CMP response validation uses attacker-controlled DN as format string, causing client DoSsecure-packages-26.05Sep 15, 2026
FixedHighOpenSSL CMS_decrypt AES-WRAP-PAD unwrap mis-sized buffer causes 8-byte out-of-bounds heap writesecure-packages-26.05Sep 15, 2026
FixedHighOpenSSL DTLS buffers entire read buffers for future-epoch handshake records, causing memory amplification DoSsecure-packages-26.05Sep 15, 2026
FixedHighNULL-pointer dereference in RPK-only TLS configs upon signature_algorithms_cert extension, causing DoSsecure-packages-26.05Sep 15, 2026
FixedMediumGStreamer gst-plugins-good avidemux vprp parser OOB read via crafted AVI causes DoSsecure-packages-25.11Sep 15, 2026
FixedHighPYSEC-2026-3072: ReDoS via catastrophic backtracking in soupsieve attribute value regex on unterminated quotessecure-packages-25.11Sep 15, 2026
FixedHighPYSEC-2026-3071: Soupsieve unbounded memory allocation parsing large comma-separated selectors enables DoS via amplificationsecure-packages-25.11Sep 15, 2026
FixedHighGHSA-836r-79rf-4m37: soupsieve CSS selector parser ReDoS: catastrophic backtracking on unterminated quoted attribute valuesecure-packages-25.11Sep 15, 2026
FixedHighGHSA-2wc2-fm75-p42x: Soupsieve CSS parser allocates unbounded memory for large comma-separated selector lists, causing DoSsecure-packages-25.11Sep 15, 2026

Contact sales

Provide us with some basic details and we'll follow up with you about , usually within one business day.

We'll only use this to get back to you. See our privacy policy (opens in a new tab). This site is protected by reCAPTCHA and the Google Privacy Policy (opens in a new tab) and Terms of Service (opens in a new tab) apply.