Search CVE reports


Toggle filters

21 – 30 of 1649 results


CVE-2026-54909

Medium priority
Needs evaluation

pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing paths, allowing remote denial of...

2 affected packages

golang-github-pion-stun, golang-github-pion-stun-v3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-pion-stun Needs evaluation Needs evaluation Not in release
golang-github-pion-stun-v3 Needs evaluation Not in release Not in release
Show less packages

CVE-2026-53587

Medium priority
Fixed

[Unknown description]

1 affected package

libgit2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-53586

Medium priority
Fixed

[Unknown description]

1 affected package

libgit2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2026-53585

Medium priority
Fixed

[Unknown description]

1 affected package

libgit2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-53584

Medium priority

Some fixes available 4 of 6

[Unknown description]

1 affected package

libgit2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Fixed Fixed Fixed Fixed Ignored
Show less packages

CVE-2026-53583

Medium priority
Needs evaluation

[Unknown description]

1 affected package

libgit2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-54345

Medium priority
Needs evaluation

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a...

2 affected packages

golang-github-gopacket-gopacket, gopacket

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-gopacket-gopacket Needs evaluation Needs evaluation Not in release
gopacket Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-54332

Medium priority
Needs evaluation

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes...

2 affected packages

golang-github-gopacket-gopacket, gopacket

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-gopacket-gopacket Needs evaluation Needs evaluation Not in release
gopacket Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-49478

Medium priority
Needs evaluation

[Unknown description]

1 affected package

golang-github-sigstore-fulcio

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-sigstore-fulcio Needs evaluation Not in release Not in release
Show less packages

CVE-2026-49835

Medium priority
Needs evaluation

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for...

1 affected package

golang-github-sigstore-timestamp-authority

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-sigstore-timestamp-authority Needs evaluation Not in release Not in release
Show less packages