Search CVE reports


Toggle filters

1 – 10 of 1513 results


CVE-2026-2370

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2026-32287

Medium priority
Needs evaluation

Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level selectors such as "1=1" or "true()".

1 affected package

golang-github-antchfx-xpath

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-antchfx-xpath Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-32286

Medium priority
Needs evaluation

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

1 affected package

golang-github-jackc-pgproto3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-jackc-pgproto3 Needs evaluation Not in release
Show less packages

CVE-2026-32285

Medium priority
Needs evaluation

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

1 affected package

golang-github-buger-jsonparser

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-buger-jsonparser Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-13436

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to cause a denial of service due...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages

CVE-2026-4645

Medium priority
Not affected

Rejected reason: Duplicate of CVE-2026-32287

2 affected packages

golang-github-antchfx-xpath, golang-golang-x-vuln

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-antchfx-xpath Not affected Not affected Not affected
golang-golang-x-vuln Not affected Not in release
Show less packages

CVE-2026-32953

Medium priority
Needs evaluation

Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the tkeyclient Go module which causes 1 out of every 256 User Supplied Secrets (USS) to be silently ignored,...

1 affected package

golang-github-tillitis-tkeyclient

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-tillitis-tkeyclient Not in release Not in release
Show less packages

CVE-2026-30836

Medium priority
Needs evaluation

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue...

1 affected package

golang-github-smallstep-certificates

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-smallstep-certificates Needs evaluation Not in release
Show less packages

CVE-2026-4427

Medium priority
Not affected

Rejected reason: Duplicate of CVE-2026-32286

1 affected package

golang-github-jackc-pgproto3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-jackc-pgproto3 Not affected Not in release
Show less packages

CVE-2026-1182

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to gain unauthorized access to confidential...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release
Show less packages